RE: [VulnWatch] SSH login attempts: tcpdump packet capture
"Andrew Sledge" <[email protected]> Mon, 2 Aug 2004 08:18:59 -0400
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Organization | Georgia Perimeter College |
| Message-ID | <000501c4788a$e40ddbf0$22081e0a@PC5016733> |
I think that there may be some folks out there doing this. I have seen a thread (http://www.dslreports.com/forum/remark,10854834~mode=flat) about this. Its coming from a couple of TLDs from Europe and Asia and doesn't seem to be threatening as long as you have the box locked down properly. Sledge -----Original Message----- From: Jay Libove [mailto:[email protected]] Sent: Sunday, August 01, 2004 1:15 PM To: [email protected] Subject: [VulnWatch] SSH login attempts: tcpdump packet capture I got a packet capture of one of the SSH2 sessions trying to log in as a couple of illegal usernames. The contents of one packet suggests an attempt to buffer overflow the SSH server; ethereal's SSH decoding says "overly large value". It didn't seem to work against my system (I see no strange processes running; all files changed in past ten days look normal). I am cross-posting this message and the attached tcpdump packet capture file to the following places to let better people than I analyze it: [email protected] [email protected] [email protected] [email protected] -Jay Libove, CISSP