The following log shows an actual hacking attempt against one of our servers.
Over 680 attempts were made in just 154 seconds. Information has been changed
to protect the confidentiality of all parties involved. This hacker is running
'script kiddie' tools that allow anyone with the ability to run a program
and provide a web site name to attempt a hack. Note that only the hacking
attempts are shown in this log. All other data has been removed.
The hacker has not been successful but it illustrates why patches must always
be installed. This attempt searches for known breaches in almost every possible
combination of popular operating systems, applications, perl scripts, and
servers.
Analysis of the hacker:
This guy wants in. He or friends in the same 'B' class of IP numbers have
been attempting to breach one particular server for over a month now. If
we assume a rate of 4.4 hacking attempts per second we can see that we are
looking at an assault rate of over 11 million attempts per month. We have
determined that this user is on a dial-up connection. If the user had a
faster connection we would likely see far more robust attacks.
This is the perfect example of why security is needed. Most people assume
that because there are so many people on the Internet that by anonymity
alone they wont be targeted. However, because hacking tools are so common
and user friendly, you can quickly see that one user alone has to potential
launch 11 million attacks. If this user had a DSL or cable connection he
could potentially launch 1 billion attempts per month. If this user and
a few friends instead focused on one particular security hole they could
attempt to breach every machine on the internet in a relatively short period
of time.