Monday, December 22, 2008

The Slow Bruteforce Botnet(s) May Be Learning

Posted by kdawson on Sunday December 21, @10:30PM

from the knock-who's-there-knock dept.
SecurityIT
badger.foo writes"We've seen stories about the slow bruteforcers — we've discussed it here — and based on the data, my colleague Egil Möller was the first to suggest that since we know the attempts are coordinated, it is not too far-fetched to assume that the controlling system measures the rates of success for each of the chosen targets and allocates resources accordingly. (The probes of my systems have slowed in the last month.) If Egil's assumption is right, we are seeing the bad guys adapting. And they're avoiding OpenBSD machines."For fans of raw data, here are all the log entries (3MB) that badger.foo has collected since noticing the slow bruteforce attacks.

No comments: