Most common account names used in ssh brute force attacks
- by Charles Stewart
Does anyone maintain lists of the most frequently guessed account names that are used by attackers brute-forcing ssh?
For your amusement, from my main server's logs over the last month (43 313 failed ssh attempts), with root not getting as far as sshd:
cas@txtproof:~$ grep -e sshd /var/log/auth* | awk ' { print $8 }' | sort | uniq -c | sort | tail -n 13
32 administrator
32 stephen
34 administration
34 sales
34 user
35 matt
35 postgres
38 mysql
42 oracle
44 guest
86 test
90 admin
16513 checking