On Tue, Dec 09, 2025 at 12:45:56PM +0100, Hans-Martin Mosner via mailop wrote:
> Am 09.12.25 um 12:11 schrieb Alessandro Vesely via mailop:
> > 
> > 
> > Is this a non-exploitative password trading?
> 
> They are probably collecting compromised passwords to use them later in a 
> larger campaign. Good that you got them early!

That would be my guess too. 

Come to think of it I do not actually have hard data to back it up, but I 
*think* that my
upping the time to live for blocklisting as described in 
https://nxdomain.no/~peter/badness_enumerated_by_robots.html
to six weeks has somewhat mitigated the problem (or at least helped the noise 
level a quite 
a bit)

- Peter

-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
https://nxdomain.no/~peter/blogposts https://nostarch.com/book-of-pf-4th-edition
"Remember to set the evil bit on all malicious network traffic"
delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.
_______________________________________________
mailop mailing list
[email protected]
https://list.mailop.org/listinfo/mailop

Reply via email to