PSA don't allow ssh to a server with a public ip while there's an account with a common password on it 🤦
Luckily it looks like they just wanted to install a miner, so I cleaned all that up. But man, close call.
PSA don't allow ssh to a server with a public ip while there's an account with a common password on it 🤦
Luckily it looks like they just wanted to install a miner, so I cleaned all that up. But man, close call.
Who allows logins with passwords on publicly exposed SSH servers anyways?
Not me (anymore)
I found this article quite amusing:
https://sysdig.com/blog/fishing-for-hackers
He basically does the *opposite* of recommended security practice and sees what happens.