A while back, there was a very popular ssh brute forcing script floating around 
that used the tcl expect interpreter to impliment the brute forcing of the ssh 
client.  This is probably a modified script that uses it over a variety of 
hosts and on success sends the necessary back door files.  Also, someone 
probably has written a basic brute force generator for it, so dictionary only 
attacks will probably not succeed.  

Reply via email to