ssh login attempts...new scan tool?

phuck face <[email protected]>
Newsgroups gmane.comp.security.intrusions
Message-ID <[email protected]>
Sup folks,

i've been watching my firewall logs a lot lately (home
cable link) and have had a *large* increase of hosts
attempting to login via ssh as users:

guest
admin
test
root   <-----yeah, that's what got my attention.

It appears to be automated as the same illegal users
keep showing up then, 3 login attempts on "root". Ssh
connections are coming in from various remote ports,
but none below the 1024 mark.

A gentle poking back generally shows linux hosts of
the 2.4.x or 2.5.x variety and *__ALL__* of them using
*old* versions of OpenSSH.

They are mostly from kornet.net (which i see on the
blocklist) and vsnl.net.in (india) and france although
i did get one from kanren.net (Kansas edu net), but i
called their NOC already.

Um, the interesting part is an IRC server running on
the normal 6667 port giving this response to a telnet
on that port:

:4W13e7l8c9o12m6e[email protected] NOTICE *
:psyBNC2.3BETA

So, i googled psyBNC2.3BETA and found
http://www.psychoid.lam3rz.de/ at the top of the list.
i'm reading into it more. The "lam3rz" part is kind of
a give away about what i'll find.

Has anyone else noticed this new, automated poking
about on ssh with these login attempts?

What's the story here and are these boxes getting
popped due to the old OpenSSH versions they are running?


		
__________________________________
Do you Yahoo!?
New and Improved Yahoo! Mail - Send 10MB messages!
http://promotions.yahoo.com/new_mail 
_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.