[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: sshd: Logging illegal users

On Thu, 19 Aug 2004 11:52:51 +0300 (EEST), Martin Fluch wrote:

> Do you really want to log those illegal user names? If you do so, you 
> would run into danger to log passwords in plain text as well, when you 
> accidently enter the password when ssh asks you for the user name...

I'm aware of that, but there are situations when logging the usernames
is quite interesting.
For example, if there is an increase in ssh scanning like over the
last weeks, it is nice to put a machine on the net which offers no
other services (kind of a honeypot) and see what usernames the
attackers are trying.

      - Thomas

PGP: 2047Bit RSA, ID 0x668E601D - Encrypted mail welcome!

Reply to: