Strange SSHD Behaviour

From: Naseer Bhatti (mail-lists@digitallinx.com)
Date: 09/11/02


From: "Naseer Bhatti" <mail-lists@digitallinx.com>
To: "focus-linux" <focus-linux@securityfocus.com>
Date: Thu, 12 Sep 2002 00:55:51 +0500

Hi,
I am having strange SSHD behavior. Look at the logs ..

[...]

Sep 10 01:15:33 redy sshd[5332]: scanned from 66.x.x.253 with
SSH-1.0-SSH_Version_Mapper_Servers_Alive_3.1.1043. Don't panic.
Sep 10 01:22:43 redy sshd[14100]: scanned from 66.x.x.253 with
SSH-1.0-SSH_Version_Mapper_Servers_Alive_3.1.1043. Don't panic.
Sep 10 01:23:25 redy sshd[22526]: scanned from 66.x.x.248 with
SSH-1.0-SSH_Version_Mapper_Servers_Alive_3.1.1043. Don't panic.
Sep 10 01:30:02 redy sshd[10299]: scanned from 66.x.x.248 with
SSH-1.0-SSH_Version_Mapper_Servers_Alive_3.1.1043. Don't panic.
Sep 10 01:36:50 redy sshd[24980]: scanned from 66.x.x.248 with
SSH-1.0-SSH_Version_Mapper_Servers_Alive_3.1.1043. Don't panic.

[...]

is this some sort of scanning or internal sshd behavior? I am using Open SSH
3.4 with Protocol 2 only on Linux. I am getting this from mainly 2 IPs on
the same network I am. Any help would be appreciated.

Thanks,

Naseer