RE: Uptick in SSH scanning?

"Frank Bulk" <[email protected]>
Newsgroups gmane.org.operators.internet-access
Message-ID <!&!AAAAAAAAAAAuAAAAAAAAAKTyXRN5/+lGvU59a+P7CFMBAN6gY+ZG84BMpVQcAbDh1IQAAAATbSgAABAAAABxtTKVlaQTQJvxG6/[email protected]>
According to SANs, it looks like there's been a spike:
http://isc.sans.org/port.html?port=22

Frank

-----Original Message-----
From: [email protected] [mailto:[email protected]] On
Behalf Of Chris Adams
Sent: Wednesday, September 03, 2008 9:42 PM
To: [email protected]
Subject: Uptick in SSH scanning?

Has anyone else seen a significant rise in SSH scanning in the last day
or two?  Rather than my usual short list of blocked hosts (usually under
10), I've got several hundred blocked right now, and virtually all for
SSH login attempts with invalid users.

In a handful of tests, I see most running OpenSSH 3.8p1 and 3.8.1p1
(although I've also seen newer versions, as new as 4.7).  A number (but
not all) also seem to be running Debian sarge.  Were there some
vulnerabilities in those versions that are being exploited, or are these
just systems with simple usernames and bad passwords?

--
Chris Adams <[email protected]>
Systems and Network Administrator - HiWAAY Internet Services
I don't speak for anybody but myself - that's enough trouble.
--
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list

-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.