RE: ssh login attempts...new scan tool?
"Smith, Donald" <[email protected]>
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <[email protected]> |
isc.sans.org has been monitoring this activity for over a month now. All of the ones I have seen have been weak ssh password guessing attempts. Specifically joe accounts. [email protected] GCIA pgpFingerPrint:9CE4 227B B9B3 601F B500 D076 43F1 0767 AF00 EDCC Everyday is virus day. Do you know where your recovery CDs are? Did u create them yet? > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of > Thomas T. Evans, III > Sent: Monday, August 16, 2004 9:24 AM > To: 'Intrusions List (GCIA Practicals)' > Subject: RE: [Intrusions] ssh login attempts...new scan tool? > > > I wonder if it is in response to this article: > > http://www.buzzsurf.com/surfatwork/ > > > someone looking for open ssh ports on home computers? > > Thomas T. Evans, III CCNA > Senior Network Manager > Hawk Corporation > [email protected] > 216-267-7787 Ext. 500 > Cell: 440-669-2526 > Fax: 917-464-7241 > President, MFG/Pro Midwest User Group > > "The difference between genius and stupidity is that genius > has limits" > --Albert Einstein > > > > > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of phuck face > Sent: Sunday, August 15, 2004 7:46 PM > To: [email protected] > Subject: [Intrusions] ssh login attempts...new scan tool? > > Sup folks, > > i've been watching my firewall logs a lot lately (home > cable link) and have had a *large* increase of hosts > attempting to login via ssh as users: > > guest > admin > test > root <-----yeah, that's what got my attention. > > It appears to be automated as the same illegal users > keep showing up then, 3 login attempts on "root". Ssh > connections are coming in from various remote ports, > but none below the 1024 mark. > > A gentle poking back generally shows linux hosts of > the 2.4.x or 2.5.x variety and *__ALL__* of them using > *old* versions of OpenSSH. > > They are mostly from kornet.net (which i see on the > blocklist) and vsnl.net.in (india) and france although > i did get one from kanren.net (Kansas edu net), but i > called their NOC already. > > Um, the interesting part is an IRC server running on > the normal 6667 port giving this response to a telnet > on that port: > > :4W13e7l8c9o12m6e[email protected] NOTICE * > :psyBNC2.3BETA > > So, i googled psyBNC2.3BETA and found > http://www.psychoid.lam3rz.de/ at the top of the list. > i'm reading into it more. The "lam3rz" part is kind of > a give away about what i'll find. > > Has anyone else noticed this new, automated poking > about on ssh with these login attempts? > > What's the story here and are these boxes getting > popped due to the old OpenSSH versions they are running? > > > > __________________________________ > Do you Yahoo!? > New and Improved Yahoo! Mail - Send 10MB messages! > http://promotions.yahoo.com/new_mail > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions