Wall of Noise

What is the Wall of Noise?

Our site is public, it is constantly scanned and this gives us beautiful insights into the "what".

The "what" would be: vulnerabilities, misconfigurations, credentials, forgotten backups, and vulnerable appliances.

Every night, the script evaluates the access.log from the previous day. Real visits are sorted out. Then a little "sanitize" to make IP addresses, Base64 stuff and domains unrecognizable. Only the scanner noise remains.

All times UTC. The numbers refresh once per night.

Website: Yesterday in numbers

Scanner requests yesterday: …
Of them with a fake bot identity: …
Scanner requests since the wall went up: …

Time range: …

Most probed paths

    Top fake bots

      SSH: Yesterday in numbers

      Login attempts yesterday: …
      Connections yesterday: …
      Login attempts since we started counting: …
      Connections turned away by the caps: …
      Methods password / public key: …

      Password shape

      Numeric only: …
      Equals the user name: …
      Empty: …
      Length 1 to 5: …
      6 to 8: …
      9 to 12: …
      13 and more: …

      Yesterday's pattern

      Share of attempts against root: …
      Distinct user names: …
      Passwords already tried in the last 7 days: …
      Attempts per connection: …

      Time range: …

      Most tried user names

        Most tried passwords

          Client software

            Published strings are limited to entries of a public word list, dictionary: SecLists (MIT).