Slashdot Mirror


Password Gropers Hit Peak Stupid, Take the Spamtrap Bait

badger.foo (447981) writes Peter Hansteen reports that a new distributed and slow-moving password guessing effort is underway, much like the earlier reports, but this time with a twist: The users they are trying to access do not exist. Instead, they're taken from the bsdly.net spamtrap address list, where all listed email addresses are guaranteed to be invalid in their listed domains. There is a tiny chance that this is an elaborate prank or joke, but it's more likely that via excessive automation, the password gropers have finally hit Peak Stupid.

1 of 100 comments (clear)

  1. Weird log file activity... by QuietLagoon · · Score: 1, Offtopic
    I've been seeing weird log file activity for the web server that runs some of my sites.

    .
    A lot of requests for odd URLs, all of which return 404. All of the requests that I checked originated at an IP address in Russia, and dozens of different IP addresses were used. These odd requests started about 5 or 6 months ago and have been ramping up lately. Makes me wonder just what they originators are looking for?