> I'm used to seeing SSH brute force attempts, by now, but recently I
> got one with some "interesting" usernames in it:
> Jan 23 13:54:14 sshd[14092]: Invalid user %c]# from
> Jan 23 13:54:14 sshd[14093]: input_userauth_request:
> invalid user %c]#
> Jan 23 13:54:14 sshd[14092]: pam_unix(sshd:auth): bad
> Jan 23 13:54:24 sshd[14100]: pam_succeed_if(sshd:auth):
> error retrieving information about user [%n@%m

Looks to me like a poorly written script some kiddy is using.  Stuff like %n@%m seems like parameters that should have been replaced had the luser been using the tool correctly ;-)

I've noticed a large increase in the number of spam emails coming in with subjects like %s and similar to/from  names, etc.

