2015

I bought a cheap vps to log what interactions it had — The other day I have bought a mega-super-dirt-cheap VPS ($10 for the year!) without advertising the ip or allocating a hostname to it (yet) with the intention of logging all attempts to access it (either via ssh or http for now).
I trawled through the logs of the honeypot vps — As specified in the last post, I bought a VPS with the simple intention of letting it sit idle to see what (I can only guess) automated attempts at log in and access.
Another weeks worth of logs from my honeypot VPS — A little quieter over this period.
Running denyhosts on the honeypot — Unsurprisingly, there was a significant reduction in the number of attempts as the denyhosts daemon bans IP addresses after a specific number of attempts.
Running the honeypot VPS on a non-standard port — Running the SSHD on a different port than standard, no deny hosts locking out anything led to a mere 300 attempts to login as root.
Another round of httpd logging on a server — A simple bit of bash scripting through the httpd access.log files to determine counts of URLs that have been accessed as well as the ip address that they have been accessed from.