SQL Honeypot
Your database probably shouldn’t be directly exposed on the internet. But if you did happen to slip up, here are the sort of brute force login attempts you could expect to see in your logs. This list filters the exact IPs attempting logins from the past seven days against a honeypot SQL server I’ve set up. This list is updated daily.
UPDATE: After running daily updates for over a year, I am shutting down the service. This list will remain static with the last logs posted.
SQL Login Attempt | Number of Hits |
---|
'root'@'121.41.x.x | 232 |
'root'@'142.11.x.x | 116 |
'admin'@'75.72.x.x | 116 |
'root'@'47.76.x.x | 116 |
'root'@'185.193.x.x | 116 |
'admin'@'89.121.x.x | 116 |
'admin'@'34.85.x.x | 116 |
'root'@'66.94.x.x | 116 |
'root'@'38.47.x.x | 116 |
'root'@'115.127.x.x | 116 |
'admin'@'95.165.x.x | 116 |
'user'@'80.14.x.x | 116 |
'root'@'176.196.x.x | 115 |
'root'@'87.120.x.x | 16 |
'root'@'94.156.x.x | 16 |
'root'@'37.120.x.x | 9 |
'root'@'94.156.x.x | 9 |
'Gilbert'@'87.251.x.x | 8 |
'michaela'@'87.251.x.x | 8 |
'2n6Wvq'@'87.251.x.x | 8 |
'pay'@'87.251.x.x | 8 |
'pippo'@'87.251.x.x | 8 |
'spidey'@'87.251.x.x | 8 |
'biggin'@'87.251.x.x | 8 |
'iFgHjB'@'87.251.x.x | 8 |
'56789'@'87.251.x.x | 8 |
'colleen'@'87.251.x.x | 8 |
'slippy'@'87.251.x.x | 8 |
'stave'@'87.251.x.x | 8 |
'lazarus'@'87.251.x.x | 8 |
'payton'@'87.251.x.x | 8 |
'blackbelt'@'87.251.x.x | 8 |
'scully'@'87.251.x.x | 8 |
'trident'@'87.251.x.x | 8 |
'basic'@'87.251.x.x | 8 |
'tomato'@'87.251.x.x | 8 |
'shelley'@'87.251.x.x | 8 |
'falling'@'87.251.x.x | 8 |
'Michelle'@'87.251.x.x | 8 |
'garland'@'87.251.x.x | 8 |
'puppy'@'87.251.x.x | 8 |
'porkchop'@'87.251.x.x | 8 |
'cheetah'@'87.251.x.x | 8 |
'maxime'@'87.251.x.x | 8 |
'chewie'@'87.251.x.x | 8 |
'rickster'@'87.251.x.x | 8 |
'2001'@'87.251.x.x | 8 |
'piper'@'87.251.x.x | 8 |
'Arthur'@'87.251.x.x | 8 |
'clancy'@'87.251.x.x | 8 |