Slashdot Mirror


The "Hail Mary Cloud" Is Growing

badger.foo writes "The Australian rickrolling of jailbroken iPhones only goes to prove that bad passwords are bad for you, Peter Hansteen points out, as he reports on the further exploits of the password-guessing Hail Mary Cloud (which we've discussed in the past). The article contains log data that could indicate that the cloud of distributed, password-guessing hosts is growing. 'With 1767 hosts in the current sample it is likely that we have a cloud of at least several thousand, and most likely no single guessing host in the cloud ever gets around to contacting every host in the target list. The busier your SSH deamon is with normal traffic, the harder it will be to detect the footprint of Hail Mary activity, and likely a lot of this goes undetected.'"

5 of 102 comments (clear)

  1. Wet Nuns by byrdfl3w · · Score: 5, Funny

    Hail Mary's... Deamons... Rick Astley.. The final battle is closer than we ever imagined.

  2. Re:Put in denyhosts... by Anonymous Coward · · Score: 1, Funny

    denyhosts is security through obscurity much like changing the default port for SSH... or so I'm told.

  3. Re:How to ID an Infected Computer by certain+death · · Score: 1, Funny

    You have a router in front of your iPhone?!? WOW! I have GOT to get that app.

    --
    "My immediate reaction is "WTF? What kind of moron doesn't make things 64-bit safe to begin with?" Linus
  4. Re:Denyhosts by TheRaven64 · · Score: 1, Funny

    Yes indeed. You can always make a network-facing daemon that has been heavily audited more secure by putting a Python script between it and the public Internet.

    --
    I am TheRaven on Soylent News
  5. Re:Put in denyhosts... by David+Gerard · · Score: 3, Funny

    The main role of Denyhosts is to lock you out of your own box if you're using an ssh-based file system, which applies your incorrect password multiple times rather than once. I've spent way too much time going into my hosted box via somewhere else to let myself back in.

    --
    http://rocknerd.co.uk