AW: sshd bruteforce from 66.246.72.184

"Philipp Vogt" <[email protected]> Tue, 22 Feb 2005 10:53:00 +0100
Newsgroups gmane.comp.security.intrusions
Message-ID <20050222095300.ISKV6920.viefep13-int.chello.at@VOGGEWIN2K>
 
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello!

  Hmm... I'm sorry but I only have a Homelan but such "attacks" are
pretty common for me. I experience them about 2 or 3 times a week.
Yesterday evening someone from 198.31.193.194 (host.onoc.net) tried
to get in. The usernames s/he/they were pretty few. I think there a
different usernamelists in use. 

  It seems like portscans are out and bruteforcing ssh is the new
hype :-)

  Just my 2 cents.

[email protected] wrote:
> we have experienced co-ordinatded bruteforce ssh attempts
> to access our servers
> 
> all packets from the offending IP have been blocked at our
> firewalls and will no longer be able to access any services
> provided by our organization
> 
> Attack time 0734 - 0854 CST
> 
> this attack is considered a targeted attempt on our servers.
> 
> either the individual attempted to individually attack
> 
> 205.200.75.113
> 205.200.160.150
> 205.200.160.250
> 
> OR the individual attacked
> 
> 205.200.75.113 on unpublished ports that redirect
> ssh to the target machines
> 
> kenneth gf brown
> ceo shadowplay.net
> 
[log snipped]

regards

  Philipp

- -- 
Philipp Vogt
Student
Informatik TU-Wien
EMail : [email protected]
pgp fingerprint: F8B3 EFF8 C6D2 31E1 E855  3959 942D 24EA D66B B8A4
pgp-schluessel:  http://members.chello.at/philipp.vogt/vogge.asc

-----BEGIN PGP SIGNATURE-----
Version: PGP 8.1

iQA/AwUBQhsA++OzKhTmfGETEQKkfQCeIHszwGrBXwFC+hDA0xCnBNcuNHIAoJlJ
nMf0qksceVY07RNBD1pY3qvM
=HPJe
-----END PGP SIGNATURE-----

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions