I recently got around to setting up "Logwatch" on a few of my servers, and I found it interesting to see how many times a day our servers get attempted SSH authentication. The usernames seem to be quite random, though the IP addresses used are 90% of the time from China. This got me thinking...
Why is it just the Chinese? - Is it easier for them to do, as in less laws regarding this, or the fact that its harder to take action against them..
What do they do when they are successful? - Is it added to a botnet that further attacks other servers, or does it sit idle waiting for a seemingly "homegrown DDoS".
Has anyone attempted to leave a computer open as a "Honeypot" to see what activities they engage in?
Why is it just the Chinese? - Is it easier for them to do, as in less laws regarding this, or the fact that its harder to take action against them..
What do they do when they are successful? - Is it added to a botnet that further attacks other servers, or does it sit idle waiting for a seemingly "homegrown DDoS".
Has anyone attempted to leave a computer open as a "Honeypot" to see what activities they engage in?