Re: ssh login attempts...new scan tool?
"earthdog" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <005e01c48497$c95474e0$d30cf118@oemcomputer> |
here is just ONE of the replies re: Canada...so watch it! ----- Original Message ----- From: "Timothy Chase" <[email protected]> To: "Intrusions List (GCIA Practicals)" <[email protected]> Sent: Monday, August 16, 2004 3:26 PM Subject: Re: [Intrusions] ssh login attempts...new scan tool? > On Full Disclosure and VulnWatch, they were discussing something along > these lines fairly recently. Messages I saw were from July 25 - Aug > 1. Automated attempts at login through SSH. Most of the sources were > in Canada and Italy for at least one individual who was witnessing > this. It seems that all of the machines which were launching these > attacks had been rooted. > > On Mon, 16 Aug 2004 11:24:12 -0400, Thomas T. Evans, III > <[email protected]> wrote: > > I wonder if it is in response to this article: > > > > http://www.buzzsurf.com/surfatwork/ > > > > someone looking for open ssh ports on home computers? > > > > Thomas T. Evans, III CCNA > > Senior Network Manager > > Hawk Corporation > > [email protected] > > 216-267-7787 Ext. 500 > > Cell: 440-669-2526 > > Fax: 917-464-7241 > > President, MFG/Pro Midwest User Group > > > > "The difference between genius and stupidity is that genius has limits" > > --Albert Einstein > > > > > > > > > > -----Original Message----- > > From: [email protected] > > [mailto:[email protected]] On Behalf Of phuck face > > Sent: Sunday, August 15, 2004 7:46 PM > > To: [email protected] > > Subject: [Intrusions] ssh login attempts...new scan tool? > > > > Sup folks, > > > > i've been watching my firewall logs a lot lately (home > > cable link) and have had a *large* increase of hosts > > attempting to login via ssh as users: > > > > guest > > admin > > test > > root <-----yeah, that's what got my attention. > > > > It appears to be automated as the same illegal users > > keep showing up then, 3 login attempts on "root". Ssh > > connections are coming in from various remote ports, > > but none below the 1024 mark. > > > > A gentle poking back generally shows linux hosts of > > the 2.4.x or 2.5.x variety and *__ALL__* of them using > > *old* versions of OpenSSH. > > > > They are mostly from kornet.net (which i see on the > > blocklist) and vsnl.net.in (india) and france although > > i did get one from kanren.net (Kansas edu net), but i > > called their NOC already. > > > > Um, the interesting part is an IRC server running on > > the normal 6667 port giving this response to a telnet > > on that port: > > > > :4W13e7l8c9o12m6e[email protected] NOTICE * > > :psyBNC2.3BETA > > > > So, i googled psyBNC2.3BETA and found > > http://www.psychoid.lam3rz.de/ at the top of the list. > > i'm reading into it more. The "lam3rz" part is kind of > > a give away about what i'll find. > > > > Has anyone else noticed this new, automated poking > > about on ssh with these login attempts? > > > > What's the story here and are these boxes getting > > popped due to the old OpenSSH versions they are running? > > > > __________________________________ > > Do you Yahoo!? > > New and Improved Yahoo! Mail - Send 10MB messages! > > http://promotions.yahoo.com/new_mail > > _______________________________________________ > > Intrusions mailing list > > [email protected] > > http://www.dshield.org/mailman/listinfo/intrusions > > > > _______________________________________________ > > Intrusions mailing list > > [email protected] > > http://www.dshield.org/mailman/listinfo/intrusions > > > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions Defend your privacy! Encrypt your email today! http://www.bytefusion.com/secexmail _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions