Re: iptables & tcp wrappers

From: Tom Walsh (mailinglist_at_expresshosting.net)
Date: 10/02/04

  • Next message: Luis M: "Re: iptables & tcp wrappers"
    To: <focus-linux@securityfocus.com>
    Date: Fri, 1 Oct 2004 23:18:35 -0500
    
    

    > Im getting also frequent attempts to log into ssh on some servers using
    > those exact usernames from different ip's. Its it a worm or just some
    > new h4x0r tool ? anyone ?

    It is nothing more than a compiled "tool" for hackers. Requires zero skill
    to compile it and run it against a range of IP address.

    You can find the source in the link below.

    http://www.k-otik.com/exploits/08202004.brutessh2.c.php

    The number of attempts has gotten so bad that I have disabled SSHd from
    listening on the external interfaces of our servers much like you suggested,
    Francisco.

    Tom Walsh
    eXpressHosting


  • Next message: Luis M: "Re: iptables & tcp wrappers"

    Relevant Pages

    • Nimda Worm Alert - What Ive done so far.
      ... Download/Install URL Scan for www servers. ... A new worm named W32/Nimda-A (known aliases are Nimda, Minda, Concept ... Microsoft IIS 4.0/5.0 File Permission Canonicalization Vulnerability ...
      (Focus-Microsoft)
    • Re: ** Sobig.F attack expected 3:00pm to 6:00pm EST today [Friday 22]
      ... computers that are currently infected with the Sobig.F worm ... > infected device possibly involving the "master servers," the others opened ... > This press release comes from F-Secure. ... > has been added to our lists without your consent, ...
      (microsoft.public.inetserver.iis.security)
    • Re: ** Sobig.F attack expected 3:00pm to 6:00pm EST today [Friday 22]
      ... computers that are currently infected with the Sobig.F worm ... > infected device possibly involving the "master servers," the others opened ... > This press release comes from F-Secure. ... > has been added to our lists without your consent, ...
      (microsoft.public.windowsxp.security_admin)
    • Re: ** Sobig.F attack expected 3:00pm to 6:00pm EST today [Friday 22]
      ... computers that are currently infected with the Sobig.F worm ... > infected device possibly involving the "master servers," the others opened ... > This press release comes from F-Secure. ... > has been added to our lists without your consent, ...
      (microsoft.public.security)
    • RE: New "concept" virus/worm?
      ... The W32.Nimda.A@mm worm infects IIS servers by exploiting the 'MS IIS/PWS ... opening the attachment will infect the machine. ... The virus comes at a time of heightened sensitivity to Internet attack. ...
      (Vuln-Dev)