RE: sshd bruteforce from 66.246.72.184
"kenneth gf brown" <[email protected]> Mon, 21 Feb 2005 13:23:09 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <066b01c5184a$c997ea30$1a0a0a0a@gobo> |
pehr.. thnx for the input... the failed passwords for illegal accounts guest temp etc. sshd is locked down to not allow root and/or admin sshd logins on the box. tyvm been doing this a while... :) just cuz an account is "there" ie not illegal doesnt mean you can login to it... also not having the accounts there doesnt stop people knocking on the doors to see if they are there... you'd just get a whack load of "illegal" users... its what happens when scriptkiddies dl their skilz its still a directed brute force attack on 3 servers across 2 remote B classes... (we have confirmed that it's did not hit our redirection ports) within the same time period, so they targeted us, it was worth the report to the isp's abuse team and to intrusions for co-relation with others. if one person registers a heads up others can look for simmilar traffic on their nets. I have found that it pays to be open about such issues. kenneth gf brown ceo shadowplay.net > > If I am reading this log correctly you have some pretty > obvious account names. It might be a good idea to look over > your servers and remove accounts such as root and admin and > replace them with dummy accounts. The security gain might be > small, but it stops password guessing and makes it somewhat > harder for an attacker if he penetrates one of your systems. > > -- > /Pehr Söderman > [email protected] > Student of Computer Science > Royal Institute of Technology, Stockholm, Sweden > Erasmus student at Universität Karlsruhe, Germany > > Cum catapultae proscriptae erunt tum soli proscript > catapultas habebunt. > > > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > > > __________ NOD32 1.1004 (20050221) Information __________ > > This message was checked by NOD32 antivirus system. > http://www.nod32.com > > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions