Skip to content
uphillsecurity.com·

🔒Honeypot Logs 1.5M SSH Attempts in 30 Days

Your server's most vulnerable moment is when it boots up

TL;DR

A honeypot setup for 30 days logged over 1.5 million SSH login attempts, highlighting the critical need for robust security measures during server initialization.

In a month-long experiment, a honeypot network with 15 servers recorded an astounding 1,531,053 SSH login attempts from unique IPs across the globe. The data reveals Asia as the primary source of attacks (60.2%), followed by Europe and North America. With over 131,922 unique credentials attempted, it's clear that default usernames like 'root' are still a common target. This highlights the importance of securing SSH access during server setup to prevent unauthorized access.

Key Points

1

30-day honeypot network with 15 servers recorded over 1.5 million SSH login attempts

2

Asia accounted for 60.2% of total login attempts, followed by Europe (29.6%) and North America (6.4%)

3

Unique IP addresses from China made up 24.3%, the highest among countries

4

Top credentials attempted included 'root' with 3861 instances and 'admin:123456'

5

AS48090 TECHOFF SRV LIMITED had the highest attempts per IP at 11,107.9

Why It Matters

If you're setting up a new server with SSH access, this data shows why securing it immediately is critical. Default credentials like 'root' are still heavily targeted, and attacks peak from Asia. Smaller teams may overlook these risks but should consider multi-factor authentication (MFA) for added security.

sshhoneypotlogin-attemptsserver-securityattack-sources

Frequently Asked Questions

Why does this matter?

If you're setting up a new server with SSH access, this data shows why securing it immediately is critical. Default credentials like 'root' are still heavily targeted, and attacks peak from Asia. Smaller teams may overlook these risks but should consider multi-factor authentication (MFA) for added security.

What happened?

A honeypot setup for 30 days logged over 1.5 million SSH login attempts, highlighting the critical need for robust security measures during server initialization.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 2,544 builders reading daily.