• Cybercriminals Abuse Vibe Coding Service to Create Malicious Sites darkreadingRob Wright
    • FBI, Cisco Warn of Russian Attacks on 7-Year-Old Flaw darkreadingJai Vijayan, Contributing Writer
    • How Outer Space Became the Next Big Attack Surface darkreadingAlexander Culafi
    • Incode Acquires AuthenticID to Enhance AI-Driven Identity Verification darkreadingFahmida Y. Rashid
    • DOM-Based Extension Clickjacking Exposes Popular Password Managers to Credential and Data Theft The Hacker [email protected] (The Hacker News)
    • The Beginner’s Guide to Using AI: 5 Easy Ways to Get Started (Without Accidentally Summoning Skynet)
      by Tech Jacks
      March 29, 2025
    • Tips and Tricks to Enhance Your Incident Response Procedures
      by Tech Jacks
      March 17, 2025
    • Building a Security Roadmap for Your Company: Strategic Precision for Modern Enterprises 
      by Tech Jacks
      March 10, 2025
    • The Power of Policy: How Creating Strong Standard Operating Procedures Expedites Security Initiatives
      by Tech Jacks
      March 6, 2025
    • Building a Future-Proof SOC: Strategies for CISOs and Infosec Leaders 
      by Tech Jacks
      March 3, 2025
    • Security Gate Keeping – Annoying – Unhelpful
      by Tech Jacks
      November 13, 2024

  • Home
  • Blog & Observations
  • Articles
    • Guest Author
      • Peter Ramadan
        • SOC IT to ME
        • The Power of Policy
        • CISO Elite
  • In The News
  • Podcast & Vlogs
    • Podcast Videos
    • Security Unfiltered Podcast Information
  • Training & Videos
    • AI
      • AI Governance
    • Cloud
      • AWS
      • Azure
      • Google Cloud
    • Networking
    • Scripting
    • Security
      • Application Security
      • Cloud Security
      • Incident Response
      • Pentesting Information
      • Risk Management
      • Security Policy
    • Servers
    • Microsoft SCCM
    • ISC2
  • Services

Airtell Router Scans, and Mislabeled usernames, (Wed, Aug 20th) SANS Internet Storm Center, InfoCON: green

August 20, 2025

Looking at new usernames collected by our Cowrie honeypots, you will first of all notice a number of HTTP headers. It is very common for attackers to scan for web servers on ports that are covered by our Telnet honeypots. The result is that HTTP request headers end up in our username and password database. 

Looking at new usernames collected by our Cowrie honeypots, you will first of all notice a number of HTTP headers. It is very common for attackers to scan for web servers on ports that are covered by our Telnet honeypots. The result is that HTTP request headers end up in our username and password database. 

This morning, I noticed another interestingly looking username: Airtel@123 [1]. We do see it used with “passwords” like root, otx, and itmuser.

A quick Google search confirmed that “Airtel@123” is the password, and the username is likely “admin”, which is not even in the list above. There is another odd thing the attacker may have overlooked here: Based on the documentation I could find, “Airtel@123” is not the telnet/ssh password for the Airtell Zerotouch router. Instead, it appears to be the Wifi default password. The login defaults to the less creative “admin”/”admin”.

And while we are at it, here are a few more “interesting but useful” usernames and passwords I have seen:

‘”username”' – Maybe someone parsing a random password list that was HTML encoded? Or someone trying to XSS our site?

echo ‘Connection established’ – no, it wasn’t. Likely a check to see if the login succeeded.

‘”root”‘ – even double quotes got escaped correctly. I still think this is more bad parsing of a username list, and not an XSS attack.

usernane “$oot” and password “$dmin”. Interesting… No idea if that will work, but anybody got any ideas why someone may try this?

For a full list of recent usernames, see https://isc.sans.edu/data/allsshusernames.html. Let me know if you spot anything interesting.

 

[1] https://isc.sans.edu/ssh_usernames.html?username=QWlydGVsQDEyMw%3D%3D

—
Johannes B. Ullrich, Ph.D. , Dean of Research, SANS.edu
Twitter|

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. 

​Read More

Share this:

  • Click to share on X (Opens in new window) X
  • Click to share on Reddit (Opens in new window) Reddit
  • Click to share on LinkedIn (Opens in new window) LinkedIn
  • Click to share on Facebook (Opens in new window) Facebook
  • Click to email a link to a friend (Opens in new window) Email

Like this:

Like Loading...
Share

In The News

Tech Jacks
Derrick Jackson is a IT Security Professional with over 10 years of experience in Cybersecurity, Risk, & Compliance and over 15 Years of Experience in Enterprise Information Technology

Leave A Reply


Leave a Reply Cancel reply

You must be logged in to post a comment.

This site uses Akismet to reduce spam. Learn how your comment data is processed.

  • Blog

    • Security Gate Keeping - Annoying - Unhelpful
      November 13, 2024
    • 15 Years on LinkedIn: An Authentic Reflection(or a Beauty...
      October 24, 2024
    • Podcast & Cloud Security Governance
      February 24, 2021
    • The Journey Continues - Moving through 2021
      January 5, 2021
    • CISSP Journey
      February 22, 2019




  • About TechJacks
  • Privacy Policy
  • Gaming Kaiju
© Copyright Tech Jacks Solutions 2025

%d