AW: sshd bruteforce from 66.246.72.184
"Philipp Vogt" <[email protected]> Tue, 22 Feb 2005 10:53:00 +0100
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <20050222095300.ISKV6920.viefep13-int.chello.at@VOGGEWIN2K> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello! Hmm... I'm sorry but I only have a Homelan but such "attacks" are pretty common for me. I experience them about 2 or 3 times a week. Yesterday evening someone from 198.31.193.194 (host.onoc.net) tried to get in. The usernames s/he/they were pretty few. I think there a different usernamelists in use. It seems like portscans are out and bruteforcing ssh is the new hype :-) Just my 2 cents. [email protected] wrote: > we have experienced co-ordinatded bruteforce ssh attempts > to access our servers > > all packets from the offending IP have been blocked at our > firewalls and will no longer be able to access any services > provided by our organization > > Attack time 0734 - 0854 CST > > this attack is considered a targeted attempt on our servers. > > either the individual attempted to individually attack > > 205.200.75.113 > 205.200.160.150 > 205.200.160.250 > > OR the individual attacked > > 205.200.75.113 on unpublished ports that redirect > ssh to the target machines > > kenneth gf brown > ceo shadowplay.net > [log snipped] regards Philipp - -- Philipp Vogt Student Informatik TU-Wien EMail : [email protected] pgp fingerprint: F8B3 EFF8 C6D2 31E1 E855 3959 942D 24EA D66B B8A4 pgp-schluessel: http://members.chello.at/philipp.vogt/vogge.asc -----BEGIN PGP SIGNATURE----- Version: PGP 8.1 iQA/AwUBQhsA++OzKhTmfGETEQKkfQCeIHszwGrBXwFC+hDA0xCnBNcuNHIAoJlJ nMf0qksceVY07RNBD1pY3qvM =HPJe -----END PGP SIGNATURE----- _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions