<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacked &#8211; SSH Bruteforce</title>
	<atom:link href="http://www.shellperson.net/hacked-ssh-bruteforce/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.shellperson.net/hacked-ssh-bruteforce/</link>
	<description>Help me keep the shell people alive.</description>
	<lastBuildDate>Sat, 04 May 2013 21:26:19 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: coder33</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-41417</link>
		<dc:creator>coder33</dc:creator>
		<pubDate>Mon, 15 Oct 2012 21:56:36 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-41417</guid>
		<description><![CDATA[THE SCAN AS FOLLOW FROM IP 
./go.sh 211
./GO-SH +IP &lt;&gt; START SCAN FROM 211.0.0.1 --- TO --- 211.255.255.255
AFTER GET THE RESULT AND FIND PORT 22 OPEN ON SOME IP 
PROGRAM MAKE CHECK THE IP WITH PASS FILE CALLD 
pass_file &lt;&lt;&gt;&gt;

root /root
root/admin
root/guest
root/123

:D]]></description>
		<content:encoded><![CDATA[<p>THE SCAN AS FOLLOW FROM IP<br />
./go.sh 211<br />
./GO-SH +IP &lt;&gt; START SCAN FROM 211.0.0.1 &#8212; TO &#8212; 211.255.255.255<br />
AFTER GET THE RESULT AND FIND PORT 22 OPEN ON SOME IP<br />
PROGRAM MAKE CHECK THE IP WITH PASS FILE CALLD<br />
pass_file &lt;&lt;&gt;&gt;</p>
<p>root /root<br />
root/admin<br />
root/guest<br />
root/123</p>
<p>:D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: coder33</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-41416</link>
		<dc:creator>coder33</dc:creator>
		<pubDate>Mon, 15 Oct 2012 21:52:11 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-41416</guid>
		<description><![CDATA[the  MFU.TXT its the ip range the hacker scan it for ssh scanner its  ssh-root scanner
the result must be in txt calld &quot; VULN.TXT &quot;
ITS OLD KIND OF SSH SCANNER BY ROMANIAN HACKER TEAM 
THY HAVE NOW NEW ONE AND MORE STRONGER IN ARAB TEAM AND INDONESIAN TEAM ......]]></description>
		<content:encoded><![CDATA[<p>the  MFU.TXT its the ip range the hacker scan it for ssh scanner its  ssh-root scanner<br />
the result must be in txt calld &#8221; VULN.TXT &#8221;<br />
ITS OLD KIND OF SSH SCANNER BY ROMANIAN HACKER TEAM<br />
THY HAVE NOW NEW ONE AND MORE STRONGER IN ARAB TEAM AND INDONESIAN TEAM &#8230;&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Martin</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-36965</link>
		<dc:creator>Martin</dc:creator>
		<pubDate>Fri, 10 Aug 2012 00:20:08 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-36965</guid>
		<description><![CDATA[You can install Fail2Ban and block all IPs which are have more than xxx failures and report the Attacker automatically over https://www.blocklist.de to the Provider.]]></description>
		<content:encoded><![CDATA[<p>You can install Fail2Ban and block all IPs which are have more than xxx failures and report the Attacker automatically over <a href="https://www.blocklist.de" rel="nofollow">https://www.blocklist.de</a> to the Provider.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: me</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-32787</link>
		<dc:creator>me</dc:creator>
		<pubDate>Thu, 14 Jun 2012 23:18:10 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-32787</guid>
		<description><![CDATA[There are a lot of vulnerabilities , not only bruteforce on ssh 22. They can get into your computer through Apache or phpMyAdmin vulnerabilities and much more.]]></description>
		<content:encoded><![CDATA[<p>There are a lot of vulnerabilities , not only bruteforce on ssh 22. They can get into your computer through Apache or phpMyAdmin vulnerabilities and much more.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chip</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-31318</link>
		<dc:creator>Chip</dc:creator>
		<pubDate>Mon, 21 May 2012 17:52:14 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-31318</guid>
		<description><![CDATA[Hi guys! I just saw what you wrote. Unfortunately most of the so called &quot;hackers&quot; are from Eastern Europe(e.g:Macedonia, Bulgaria, Romania,etc.) They are just your machine to gain access to another machines and so on... Probably you have a weak password(pass, password, 123456, root...so on) and do not have installed honeypot. Try installing honeypot and keeping your system up-to-date. It always helps. Another personal point of view is that if you disable root login it will be safe. Another idea would be to uninstall commands editor (pico, nano) and also wget, apt-get, yum, ftp and stuff like this. If you don&#039;t allow him to access external links he will find your machine useless and move on to the next one.
Best Regards,
Chip.]]></description>
		<content:encoded><![CDATA[<p>Hi guys! I just saw what you wrote. Unfortunately most of the so called &#8220;hackers&#8221; are from Eastern Europe(e.g:Macedonia, Bulgaria, Romania,etc.) They are just your machine to gain access to another machines and so on&#8230; Probably you have a weak password(pass, password, 123456, root&#8230;so on) and do not have installed honeypot. Try installing honeypot and keeping your system up-to-date. It always helps. Another personal point of view is that if you disable root login it will be safe. Another idea would be to uninstall commands editor (pico, nano) and also wget, apt-get, yum, ftp and stuff like this. If you don&#8217;t allow him to access external links he will find your machine useless and move on to the next one.<br />
Best Regards,<br />
Chip.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: lix</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-30201</link>
		<dc:creator>lix</dc:creator>
		<pubDate>Mon, 23 Apr 2012 02:31:20 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-30201</guid>
		<description><![CDATA[nice nice hacker not good  :Ddont hack shells nu intaleg nimica ce e acolo shell root plmeqa password go.sh i scanner ssh backgrond you cna yuzet on backtrak5 :D nige but wohh i du dat :D:DD:D:D:]]></description>
		<content:encoded><![CDATA[<p>nice nice hacker not good  :Ddont hack shells nu intaleg nimica ce e acolo shell root plmeqa password go.sh i scanner ssh backgrond you cna yuzet on backtrak5 :D nige but wohh i du dat :D:DD:D:D:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: encrypted</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-21539</link>
		<dc:creator>encrypted</dc:creator>
		<pubDate>Thu, 01 Dec 2011 23:44:48 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-21539</guid>
		<description><![CDATA[basically what everybody else said. the &quot;ss&quot; binary is designed to scan an ip range for servers with a given port open. It does thousands of scans per minute and saves the results to a text file. The other executables take an input file (the IP list) and an output file. It&#039;s most likely that if you got broken in, it was through a really simple ssh brute force (seriously, password is not a good password), a RFI exploit, or even a RCE exploit. (google them). Use your brains when setting up a server and you&#039;ll be fine.]]></description>
		<content:encoded><![CDATA[<p>basically what everybody else said. the &#8220;ss&#8221; binary is designed to scan an ip range for servers with a given port open. It does thousands of scans per minute and saves the results to a text file. The other executables take an input file (the IP list) and an output file. It&#8217;s most likely that if you got broken in, it was through a really simple ssh brute force (seriously, password is not a good password), a RFI exploit, or even a RCE exploit. (google them). Use your brains when setting up a server and you&#8217;ll be fine.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: VerycCool78</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-21464</link>
		<dc:creator>VerycCool78</dc:creator>
		<pubDate>Wed, 30 Nov 2011 16:13:24 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-21464</guid>
		<description><![CDATA[Installing and configuring Fail2Ban will help too for securing the server by blocking the IP address of somebody that tries to access the server after couples of tries.  The default is 3. this is alone is not enough but it can be added next to other suggestion that was mentioned in this blog.]]></description>
		<content:encoded><![CDATA[<p>Installing and configuring Fail2Ban will help too for securing the server by blocking the IP address of somebody that tries to access the server after couples of tries.  The default is 3. this is alone is not enough but it can be added next to other suggestion that was mentioned in this blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Daniel</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-20518</link>
		<dc:creator>Daniel</dc:creator>
		<pubDate>Sun, 06 Nov 2011 13:18:18 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-20518</guid>
		<description><![CDATA[The best way to secure you server, is to change your ssh server port, or to disable login root (they can get access to your server by an user, and use some local root exploit to gain root access). because, the ssh scaners, using the port 22 to scan victims. on my server, the ssh is using a 4 number port. like 6354. and, never get hacked. 
PS: sorry for my bad english :P]]></description>
		<content:encoded><![CDATA[<p>The best way to secure you server, is to change your ssh server port, or to disable login root (they can get access to your server by an user, and use some local root exploit to gain root access). because, the ssh scaners, using the port 22 to scan victims. on my server, the ssh is using a 4 number port. like 6354. and, never get hacked.<br />
PS: sorry for my bad english :P</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tommy</title>
		<link>http://www.shellperson.net/hacked-ssh-bruteforce/comment-page-1/#comment-19167</link>
		<dc:creator>Tommy</dc:creator>
		<pubDate>Fri, 14 Oct 2011 13:34:21 +0000</pubDate>
		<guid isPermaLink="false">http://saintsteele.wordpress.com/?p=237#comment-19167</guid>
		<description><![CDATA[Oh! This is alarming. I thought Linux has a great security in preventing hackers attack. However, there seems a way to enter into any server. While technology keeps advancing, so do the hacking techniques.  

I think these hackers use a network of proxies which make it difficult to identify from which IP they are targeting the server. While ssh is the most easily used one to gain access to remote shell, this is where we need to make it more secure.]]></description>
		<content:encoded><![CDATA[<p>Oh! This is alarming. I thought Linux has a great security in preventing hackers attack. However, there seems a way to enter into any server. While technology keeps advancing, so do the hacking techniques.  </p>
<p>I think these hackers use a network of proxies which make it difficult to identify from which IP they are targeting the server. While ssh is the most easily used one to gain access to remote shell, this is where we need to make it more secure.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
