Skip to contentExploitQuest

Lesson 1 of 3 in The Ones Who Come Back · 4 min left in this chapter

Watch Them Try

Before you stop the brute force, look at it. The auth log of any box on the internet is a wall of failed logins from addresses all over the world — and buried in it is the difference between background noise and a determined attacker, which is exactly what the next tool needs to read.

2 min read

Not yet reviewed

Rookmentor

You closed the door with keys. The knocking did not stop — it never does. Let us actually read it, because the log is where every defence from here starts.

Wrenlearner

I have never opened an auth log. What is even in it?

The wall of attempts

Every failed SSH login writes a line to /var/log/auth.log. On a box that has been online for an hour, there are hundreds of them: Failed password from addresses you have never heard of, for usernames you never created — admin, oracle, postgres, git. This is not someone after *you*. It is the whole internet, tried automatically, all the time.

In this terminal is a real auth log. Do not scroll it — that is the lesson from Linux, and it matters more here. Ask it questions. grep "Failed password" shows the attempts; pipe it to wc -l to count them; and one line in it is not a failure at all.

Your turn

This auth log is four hundred lines of login attempts. Exactly one login succeeded. Find it — print the line that says a password was *Accepted*.

you@practice
Practice shell — nothing here is real. Type 'help' to begin.

There are hundreds of Failed password lines. Is that an emergency you need to act on right now?