hack.lu 2023

Are Leaked Credentials Dumps Used by Attackers?
10-17, 13:40–13:45 (Europe/Luxembourg), Salle Europe

With all the leaked credentials found in the wild, most of them are outdated or just a compilation of smaller dumps. Are they really used against you?


I searched for some old credentials with my domain « root shell.be » and checked if they were used in brute-force attacks….

Xavier Mertens is a freelance security consultant. His day job focuses on protecting his customers' assets by providing services like incident handling, malware analysis, forensic investigations, log management, security visualisation, and OSINT). Besides his day job, Xavier is also a Senior Handler at the SANS Internet Storm Center, Certified SANS Instructor (FOR610/FOR710), security blogger and co-organiser of the BruCON security conference.