Re: SSH attacks - anyone else seen these?



See the DenyHosts script for the response - this has been going on for years. There's no specific vulnerability, it's more a strength in numbers / worm like attack. The automated attack guesses right often enough to propagate and presumably build a *nix based botnet.

ta,
Mark

Sent from my iPhone

On Oct 16, 2007, at 6:06 PM, Tim <secnews@xxxxxxxxx> wrote:

I've recently noticed this in my logs:

Oct 15 15:30:04 mysrv sshd[9563]: Bad protocol version
identification 'POST /unauthenticated//..%01/..%01/..%01/..%01/..% 01/..%01/..
%01/..%01/..%01/..%01/..%01/..%01/..%01' from 59.106.20.158

Oct 1 17:14:51 mysrv sshd[9915]: Bad protocol version
identification '\377\364\377\375\006\377\364\377\375\006\377\364\377 \375\006'
from 84.58.87.123
Oct 1 17:15:13 airrocket sshd[11982]: Bad protocol version identification ''
from 84.58.87.123

Did anyone else notice similar things? Does anyone know what vulnerability
they are attacking?

Thanks,

--
Tim




Relevant Pages

  • Re: [fw-wiz] Variations of firewall ruleset bypass via FTP
    ... didn't carry through CERT- While Mikael was nice enough to code up "proof ... instead of the "produce attack code and announce the problem method.) ... but frankly all these folks (indeed also IPF) are his ... I'm willing to admit the risk assessment and the vulnerability ...
    (Firewall-Wizards)
  • RE: how to verify whether an attack attempt is successful?
    ... Certainly the techniques of combining vulnerability assessment data with ... attack information is an excellent way to determine success. ... if its behind an in-line network IPS and there ... play into the accuracy and usefulness of the 'success' metrics your IDS ...
    (Focus-IDS)
  • Re: [Full-disclosure] [WEB SECURITY] Unicode Left/Right Pointing Double Angel Quotation Mark byp
    ... so you are probably talking 1,000+ inputs vulnerable to attack using ... observation from one particular encounter of this vulnerability to get some ... I did some research here too, and found a new Unicode ...
    (Full-Disclosure)
  • RUS-CERT Advisory 2001-08:01
    ... Vulnerabilities in several Apache authentication modules ... vulnerable to a remote SQL code injection attack. ... SQL statements or cause the database query for the password to return ... In the MySQL and Oracle cases, the impact of the vulnerability is ...
    (Bugtraq)
  • [Full-disclosure] dt_guestbook version 1.0f XSS vulnerability
    ... fully-featured message board system with admin interface. ... flaws it is possible for the remote attacker to conduct XSS attacks. ... This vulnerability can be exploited only when PHP register_globals is ... Vulnerability Impact: Attack ...
    (Full-Disclosure)

Quantcast