While reviewing my DShield honeypot logs, I noticed for the first time something strange in my list of Top Username &#;x26; Password where&#;xc2;&#;xa0;several domain name were use as password. Initially,&#;xc2;&#;xa0;I was under the impression this might be&#;xc2;&#;xa0;a parsing error by Logstash and&#;xc2;&#;xa0;decided to review the raw logs to make sure it was parsed correctly to confirm data integrity. Since username and passwords isn&#;x26;#;39;t something submitted to DShield, I reviewed my own raw logs to confirm the data was accurate and reviewed the&#;xc2;&#;xa0;capture rate of username/password combination&#;xc2;&#;xa0;for the past few weeks:
Intelligence View
SOCIAL SHARE CARD GENERATOR