RE: SSH brute forcing attacks

"Smith, Donald" <[email protected]> Tue, 17 May 2005 08:10:51 -0600
Newsgroups gmane.comp.security.intrusions
Message-ID <9921AB57EA49D242A076864C5F473D3C0180D409@itdene2km08.AD.QINTRA.COM>
The list of usernames and passwords has grown VERY large.
The last list I saw had 3400+ passwords.
The handlers had several short write-ups on this including various
mitigation techniques.



[email protected] giac 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Andrew Daviel
> Sent: Tuesday, May 17, 2005 3:18 AM
> To: [email protected]
> Subject: [Intrusions] SSH brute forcing attacks
> 
> 
> 
> FYI
> 
> A year of so ago we saw an SSH brute-forcing attack that seemed to
> try test/test, guest/guest and a couple of others against machines.
> And yes we had a machine set up for casual use with guest/guest ...
> 
> More recently we have seen more exhaustive dictionary attacks, with
> multiple attempts against root and random names for unprivileged
> accounts. Since the traffic is encrypted, and sshd does not log the
> password, I don't know what was being tried (hacked version 
> for honeypot
> required ??)
> 
> I had not initially thought that this was a significant threat, since
> sshd will not allow rapid retries and hopefully hundreds of 
> thousands of
> guesses would be required to hit a reasonably strong password.
> 
> However, this assumption may not be valid ... I think we have 
> had maybe
> 3 machines compromised in this way, from attacks running for weeks or
> months against hundreds of machines.
> 
> SInce we have, generally speaking, a need for legitimate 
> access for users
> around the world from home, travelling or working at other 
> institutions
> we allow SSH access to most non-sensitive machines.
> However, in view of these attacks I have implemented a dynamic filter
> via system-wide logging - multiple login failures across monitored
> machines will result in the source being blocked.
> 
> -- 
> Andrew Daviel, TRIUMF, Canada
> Tel. +1 (604) 222-7376  (Pacific Time)
> [email protected]
> _______________________________________________
> Intrusions mailing list
> [email protected]
> http://www.dshield.org/mailman/listinfo/intrusions
> 

_______________________________________________
Intrusions mailing list
[email protected]
http://www.dshield.org/mailman/listinfo/intrusions