Re: ssh login attempts...new scan tool? ->MyDoom
Timothy Chase <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
SANS - MyDoom Details, ssh password brute forcing. Handlers Diary July 28th 2004 Updated July 29th 2004 04:22 UTC (Handler: Johannes Ullrich) http://www.dslreports.com/forum/remark,10907420~mode=flat P.S. What's with today's spike of TCP on 539? On Sun, 15 Aug 2004 16:45:54 -0700 (PDT), phuck face <[email protected]> wrote: > Sup folks, > > i've been watching my firewall logs a lot lately (home > cable link) and have had a *large* increase of hosts > attempting to login via ssh as users: > > guest > admin > test > root <-----yeah, that's what got my attention. > > It appears to be automated as the same illegal users > keep showing up then, 3 login attempts on "root". Ssh > connections are coming in from various remote ports, > but none below the 1024 mark. > > A gentle poking back generally shows linux hosts of > the 2.4.x or 2.5.x variety and *__ALL__* of them using > *old* versions of OpenSSH. > > They are mostly from kornet.net (which i see on the > blocklist) and vsnl.net.in (india) and france although > i did get one from kanren.net (Kansas edu net), but i > called their NOC already. > > Um, the interesting part is an IRC server running on > the normal 6667 port giving this response to a telnet > on that port: > > :4W13e7l8c9o12m6e[email protected] NOTICE * > :psyBNC2.3BETA > > So, i googled psyBNC2.3BETA and found > http://www.psychoid.lam3rz.de/ at the top of the list. > i'm reading into it more. The "lam3rz" part is kind of > a give away about what i'll find. > > Has anyone else noticed this new, automated poking > about on ssh with these login attempts? > > What's the story here and are these boxes getting > popped due to the old OpenSSH versions they are running? > > __________________________________ > Do you Yahoo!? > New and Improved Yahoo! Mail - Send 10MB messages! > http://promotions.yahoo.com/new_mail > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions