RE: [VulnWatch] SSH login attempts: tcpdump packet capture

"Andrew Sledge" <[email protected]> Mon, 2 Aug 2004 08:18:59 -0400
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Organization Georgia Perimeter College
Message-ID <000501c4788a$e40ddbf0$22081e0a@PC5016733>
I think that there may be some folks out there doing this.  I have seen a
thread (http://www.dslreports.com/forum/remark,10854834~mode=flat) about
this.  Its coming from a couple of TLDs from Europe and Asia and doesn't
seem to be threatening as long as you have the box locked down properly.

Sledge

-----Original Message-----
From: Jay Libove [mailto:[email protected]] 
Sent: Sunday, August 01, 2004 1:15 PM
To: [email protected]
Subject: [VulnWatch] SSH login attempts: tcpdump packet capture


I got a packet capture of one of the SSH2 sessions trying to log in as a
couple of illegal usernames.  The contents of one packet suggests an
attempt to buffer overflow the SSH server;  ethereal's SSH decoding says
"overly large value".

It didn't seem to work against my system (I see no strange processes
running; all files changed in past ten days look normal).

I am cross-posting this message and the attached tcpdump packet capture
file to the following places to let better people than I analyze it:
	[email protected]
	[email protected]
	[email protected]
	[email protected]

-Jay Libove, CISSP