Re: Attacks on ssh port

From: Patrick Proniewski (patpro_at_patpro.net)
Date: 09/18/04

  • Next message: Craig Edwards: "Re: Re: Attacks on ssh port"
    Date: Sat, 18 Sep 2004 14:32:50 +0200
    To: Willem Jan Withagen <wjw@withagen.nl>, Liste FreeBSD-security <freebsd-security@FreeBSD.ORG>
    
    

    On 18 sept. 2004, at 14:18, Willem Jan Withagen wrote:

    > Hi,
    >
    > Is there a security problem with ssh that I've missed???
    > Ik keep getting these hords of: Failed password for root from
    > 69.242.5.195 port 39239 ssh2
    > with all kinds of different source addresses.
    >
    > They have a shot or 15 and then they are of again, but a little later
    > on they're back and keep clogging my logs.
    > Is there a "easy" way of getting these ip-numbers added to the
    > blocking-list of ipfw??

    not a ssh related problem, it's just a brute force attack, I'm
    experiencing this on every servers I have, more than 10 times a day.
    I'm really thinking about releasing the list of attackers IP to the
    public. As far as I know, it's a pack of compromised machines.

    patpro

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Craig Edwards: "Re: Re: Attacks on ssh port"

    Relevant Pages

    • Attacks on ssh port
      ... Is there a security problem with ssh that I've missed??? ... Ik keep getting these hords of: ... They have a shot or 15 and then they are of again, ...
      (FreeBSD-Security)
    • Re: Attacks on ssh port
      ... > Is there a security problem with ssh that I've missed??? ... > Ik keep getting these hords of: ... A better solution to the verbosity level would probably be to change ...
      (FreeBSD-Security)
    • Re: Attacks on ssh port
      ... >>Is there a security problem with ssh that I've missed??? ... >>they're back and keep clogging my logs. ... in this particular case these records are clogging my login error ...
      (FreeBSD-Security)
    • pam_radius fail open?
      ... “If you find a security problem -- or even if you find something which ... I mistakenly typed the line for ssh as follows: ... Here is the result when I ssh in to the server from another host: ... The thing to note is that the system did not prompt me for a password. ...
      (FreeBSD-Security)
    • Re: Random Linux SERVER hangups (production)
      ... is a regular file. ... After that, Ssh kind of works, connects up to the point of saying ... We never figured out what they replaced; sshd for sure but also some libs as many text utils would fail or segfault. ... They got in through a brute force attack on sshd; the admin didn't really pick up on it until it was too late. ...
      (comp.os.linux.misc)