Re: Reality check: IPFW sees SSH traffic that sshd does not?



David Wolfskill wrote:
<...>
This morning (in reviewing the logs from yesterday), I found a set of
580 such setup requests logged from Mar 20 19:30:06 - Mar 20 19:40:06
(US/Pacific; currently 7 hrs. west of GMT/UTC), each from 204.11.235.148
(part of a VAULT-NETWORKS netblock). The sshd on the internal machine
never logged anything corresponding to any of this.

Might be a SYN scan. I believe SSH will not log anything if a three-way
handshake has not been completed.

Of course, it would help if you provided ipfw logs to determine exactly
what kind of packets it was.

--
Tadas Miniotas
_______________________________________________
freebsd-security@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Reality check: IPFW sees SSH traffic that sshd does not?
    ... This morning (in reviewing the logs from yesterday), ... currently 7 hrs. west of GMT/UTC), ... (part of a VAULT-NETWORKS netblock). ...
    (FreeBSD-Security)
  • Re: Home Page/Nefarious Parasite/Help Mike!
    ... Thanks for reviewing those logs. ... view certain folders, I don't know what the story is. ... amateur when it comes to this stuff. ...
    (microsoft.public.security.virus)
  • Re: Ill help you if you can help me !! this is a good one -Outlook 2003-
    ... But perhaps it better to redirect to this directory that also exist in that location, I have a suspicion that that should be the default fot outlook logging. ... Anyway I am happy I found it reviewing the logs now but have not found anything obvious ... Bart ...
    (microsoft.public.outlook.installation)
  • Re: Freebsd 5.0 Named issue stops itself??
    ... > services are crahing every few hrs.. ... > Here are some logs. ... Please upgrade to FreeBSD-5.3 or later, and you will get a newer named ...
    (freebsd-questions)
  • Exch IS doubled in size overnight
    ... Suddenly my clients SBS backups took ~5 hrs to run compared to ~3 hrs before. ... When examining the logs I discovered that the IS\First Storage Group had ...
    (microsoft.public.windows.server.sbs)