10 comments

[ 0.23 ms ] story [ 9.8 ms ] thread
Having a root password of "toor" is very clever. Nobody will figure that one out.
No "credentials" are being "harvested" here. It's all worthless data, save for the statistics.
Do most installations create a git user account with login permissions?
Last time I saw this an obscure single letter root password was still "secure", now days seems like almost all non-alphanumeric chars works. % is my new root password it still has not been brute forced.
I'd be more curious to know what these SSH scanner bots actually do if they manage to log in. Automated recon, install spambot/cryptominer/phishing site, something else?
This was submitted 2 weeks ago https://news.ycombinator.com/item?id=48947548

Seems more entertaining than suitable for real analysis. At least I did not see any collected data. You can just watch what happens at this moment.

From watching it a while I came to the conclusion that adding a new authorized ssh key is a common first step.

That doesn't look to me like it would find many real credentials. It is collecting the credentials that automated bots are trying to use, some of them, perhaps many of them, will be credentials that someone somewhere is using for something, but unless you are planning an Internet wide scan yourself using those credentials to try login to something is likely to be fruitless.
(comment deleted)
Is OP here? Curious as to what they used for geolocation