RE: SSH brute forcing attacks
"Smith, Donald" <[email protected]> Tue, 17 May 2005 08:10:51 -0600
| Newsgroups | gmane.comp.security.intrusions |
|---|---|
| Message-ID | <9921AB57EA49D242A076864C5F473D3C0180D409@itdene2km08.AD.QINTRA.COM> |
The list of usernames and passwords has grown VERY large. The last list I saw had 3400+ passwords. The handlers had several short write-ups on this including various mitigation techniques. [email protected] giac > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Andrew Daviel > Sent: Tuesday, May 17, 2005 3:18 AM > To: [email protected] > Subject: [Intrusions] SSH brute forcing attacks > > > > FYI > > A year of so ago we saw an SSH brute-forcing attack that seemed to > try test/test, guest/guest and a couple of others against machines. > And yes we had a machine set up for casual use with guest/guest ... > > More recently we have seen more exhaustive dictionary attacks, with > multiple attempts against root and random names for unprivileged > accounts. Since the traffic is encrypted, and sshd does not log the > password, I don't know what was being tried (hacked version > for honeypot > required ??) > > I had not initially thought that this was a significant threat, since > sshd will not allow rapid retries and hopefully hundreds of > thousands of > guesses would be required to hit a reasonably strong password. > > However, this assumption may not be valid ... I think we have > had maybe > 3 machines compromised in this way, from attacks running for weeks or > months against hundreds of machines. > > SInce we have, generally speaking, a need for legitimate > access for users > around the world from home, travelling or working at other > institutions > we allow SSH access to most non-sensitive machines. > However, in view of these attacks I have implemented a dynamic filter > via system-wide logging - multiple login failures across monitored > machines will result in the source being blocked. > > -- > Andrew Daviel, TRIUMF, Canada > Tel. +1 (604) 222-7376 (Pacific Time) > [email protected] > _______________________________________________ > Intrusions mailing list > [email protected] > http://www.dshield.org/mailman/listinfo/intrusions > _______________________________________________ Intrusions mailing list [email protected] http://www.dshield.org/mailman/listinfo/intrusions