RE: [Full-Disclosure] Automated SSH login attempts?

From: Todd Towles (toddtowles_at_brookshires.com)
Date: 07/29/04

  • Next message: Max Valdez: "Re: [Full-Disclosure] Re: Automated SSH login attempts?"
    To: "'Juan Carlos Navea'" <loconet@gmail.com>, <full-disclosure@lists.netsys.com>
    Date: Thu, 29 Jul 2004 15:42:29 -0500
    
    

    Hey Juan, hopefully you don't have the test user on your ssh server anymore.
    You just gave the IP address, port and username =)

    -Todd

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of Juan Carlos
    Navea
    Sent: Thursday, July 29, 2004 8:38 AM
    To: full-disclosure@lists.netsys.com
    Subject: Re: [Full-Disclosure] Automated SSH login attempts?

    One of the boxes at work actually got rooted through a successful
    attempt at the account test. They later proceeded to get root through
    a local exploit. This box was badly unpdated.

    log entries..

    Jul 12 22:26:51 server sshd[12868]: Accepted password for test from
    130.15.15.239 port 1954 ssh2
    Jul 12 22:42:35 server sshd[13998]: Accepted password for test from
    216.55.164.10 port 56454 ssh2

    ...

    These were followed by more attempts at users test/guest/admin/root

    Our ISP shut us down as some other admins reported that this box was
    now attempting brute force logins on other boxes within the same
    network space. This actually included one of our other boxes which
    luckly was not rooted.

    Anyways, once we managed to bring our box back up we noticed that
    after the successful login, it proceeded to install a rootkit. In this
    case we detected SuckIt.

    After various attempts, we were able to remove SuckIt:

    [root@server .sk12]# ./sk u
    /dev/null
    Detected version: 1.3b
    Suckit uninstalled sucesfully!

    As usual for this rootkit, it had installed an exploited sshd , a
    password sniffer and infected initd and telinetd.

    More info on sk:
    >www.phrack.org/show.php?p=58&a=7

    Up to this day, we get atleast 10 brute force attempts a day on most
    of our boxes.

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Max Valdez: "Re: [Full-Disclosure] Re: Automated SSH login attempts?"

    Relevant Pages

    • Re: [fw-wiz] FW: OT? New compromise.
      ... If you suspect you have a rootkit, it shouldn't be that hard to find it, ... depending on whether you can shut down any of these boxes and run Knoppix ... Port 1863 is the port for Microsoft's Instant Messenger client ...
      (Firewall-Wizards)
    • Re: Port scan causing system crashes
      ... Well, I have such problems last year as well, on old Sun boxes. ... same result than a port scan Dos. ... Port scan causing system crashes ...
      (Pen-Test)
    • RE: Port scan causing system crashes
      ... In the thousand or so boxes I've scanned over the last year I've ... had three crash. ... Port scan causing system crashes ... port scans (or any other port scanner) causing systems to crash? ...
      (Pen-Test)
    • Re: rst-scan for portmap?
      ... >>Just the solitary RST packet, to both boxes, from the same source machine & ... >>port#, to my port 111. ... >>Combining port-scanning and OS fingerprinting, ...
      (comp.os.linux.security)
    • Re: New exchange and 3 party spam filter.
      ... I have a test user set up on exchange 2003. ... Trend Micro IMSS, and then IMSS forwards the email to port 3000 for E2K. ... Does any one know how to have the mail from E2K3 to move to port 3000 on ...
      (microsoft.public.exchange.setup)

  • Quantcast