Skip to main content
Interlocking concrete armour blocks along a harbour breakwater with waves breaking against them.
Photo by Lennard Kollossa on Unsplash
  1. Archive/

Two Weeks of a Kippo SSH Honeypot

Patrik Grobshäuser
Author
Patrik Grobshäuser
Security researcher at Assetnote / Searchlight Cyber. Before that, seven years triaging other people’s reports at HackerOne and Shopify. Hunting bugs since 2012, published as Patrik Fehrenbach until 2025.
Table of Contents

I recently set up a honeypot tool called Kippo. Kippo runs a virtual SSH environment and records every SSH brute-force attempt against the server. We started the capture on 3 November and saw about 4,000 brute-force attempts against the server; what stands out is that almost all of the login attempts came from hosts based in China.

Our research showed that almost all the attacking machines run the Windows IIS Webserver, we are not sure whether those machines are zombies (compromised hosts being used to attack others) or servers stood up deliberately to sweep wide ranges. So far we have collected about 2,500 distinct username/password combinations.

Top credentials
#

The Top 10 List of combinations is below:

UsernamePassword
rootadmin
adminpassw0rd
adminpassword
adminP@ssw0rd
adminabc123
adminadmin
adminadmin
admin1qaz@WSX
adminAdmin123!@#

Attack trends#

I collected some charts of the attack trends below.

Kippo-Graph bar chart of successful SSH honeypot logins per day during the November 2014 capture

Pie chart breaking down SSH honeypot connections by source country, dominated by China
Bar chart of SSH honeypot connection counts per geolocated source IP address
Pie chart showing the share of SSH honeypot connections contributed by each geolocated source IP address

Related