RE: ssh login attempts...new scan tool?
Meidinger Chris <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
Has anyone got sebek or similar traces of this activity? Samples of the raw decrypted packets? Is it possible that using those silly usernames is a diversion, intended to move attention away from an actual payload that is being delivered as well? It's hard to imagine that there are enough boxes on the net that really have guest/test accounts open to make a botnet. Cheers, Chris > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Timothy Chase > Sent: Monday, August 16, 2004 21:27 > To: Intrusions List (GCIA Practicals) > Subject: Re: [Intrusions] ssh login attempts...new scan tool? > > On Full Disclosure and VulnWatch, they were discussing > something along these lines fairly recently. Messages I saw > were from July 25 - Aug 1. Automated attempts at login > through SSH. Most of the sources were in Canada and Italy > for at least one individual who was witnessing this. It > seems that all of the machines which were launching these > attacks had been rooted. > > On Mon, 16 Aug 2004 11:24:12 -0400, Thomas T. Evans, III > <[email protected]> wrote: > > I wonder if it is in response to this article: > > > > http://www.buzzsurf.com/surfatwork/ > > > > someone looking for open ssh ports on home computers? > > > > Thomas T. Evans, III CCNA > > Senior Network Manager > > Hawk Corporation > > [email protected] > > 216-267-7787 Ext. 500 > > Cell: 440-669-2526 > > Fax: 917-464-7241 > > President, MFG/Pro Midwest User Group > > > > "The difference between genius and stupidity is that genius > has limits" > > --Albert Einstein > > > > > > > > > > -----Original Message----- > > From: [email protected] > > [mailto:[email protected]] On Behalf Of phuck face > > Sent: Sunday, August 15, 2004 7:46 PM > > To: [email protected] > > Subject: [Intrusions] ssh login attempts...new scan tool? > > > > Sup folks, > > > > i've been watching my firewall logs a lot lately (home > cable link) and > > have had a *large* increase of hosts attempting to login via ssh as > > users: > > > > guest > > admin > > test > > root <-----yeah, that's what got my attention. > > > > It appears to be automated as the same illegal users keep > showing up > > then, 3 login attempts on "root". Ssh connections are > coming in from > > various remote ports, but none below the 1024 mark. > > > > A gentle poking back generally shows linux hosts of the > 2.4.x or 2.5.x > > variety and *__ALL__* of them using > > *old* versions of OpenSSH. > > > > They are mostly from kornet.net (which i see on the > > blocklist) and vsnl.net.in (india) and france although i > did get one > > from kanren.net (Kansas edu net), but i called their NOC already. > > > > Um, the interesting part is an IRC server running on the > normal 6667 > > port giving this response to a telnet on that port: > > > > :4W13e7l8c9o12m6e[email protected] NOTICE * :psyBNC2.3BETA > > > > So, i googled psyBNC2.3BETA and found > > http://www.psychoid.lam3rz.de/ at the top of the list. > > i'm reading into it more. The "lam3rz" part is kind of a give away > > about what i'll find. > > > > Has anyone else noticed this new, automated poking about on > ssh with > > these login attempts? > > > > What's the story here and are these boxes getting popped due to the > > old OpenSSH versions they are running? > > > > __________________________________ > > Do you Yahoo!? > > New and Improved Yahoo! Mail - Send 10MB messages! > > http://promotions.yahoo.com/new_mail > > _______________________________________________ > > Intrusions mailing list > > [email protected] > > http://www.dshield.org/mailman/listinfo/intrusions > > > > _______________________________________________ > > Intrusions mailing list > > [email protected] > > http://www.dshield.org/mailman/listinfo/intrusions > > > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions