SSH login attempts: tcpdump packet capture

"Jay Libove" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.announce
Message-ID <[email protected]>
I got a packet capture of one of the SSH2 sessions trying to log in as a
couple of illegal usernames.  The contents of one packet suggests an
attempt to buffer overflow the SSH server;  ethereal's SSH decoding says
"overly large value".

It didn't seem to work against my system (I see no strange processes
running; all files changed in past ten days look normal).

I am cross-posting this message and the attached tcpdump packet capture
file to the following places to let better people than I analyze it:
	[email protected]
	[email protected]
	[email protected]
	[email protected]

-Jay Libove, CISSP
ssh2.tcpdump (application/octet-stream, 8.3 KB) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.