ssh scans

From: Chad Mawson (CMAWSON@woodsaitken.com)
Date: 09/28/01


Subject: ssh scans
Date: Fri, 28 Sep 2001 15:42:52 -0500
Message-ID: <6B8805064086D64E961BE89BCAFB4E771809A2@wa2.woodsaitken.com>
From: "Chad Mawson" <CMAWSON@woodsaitken.com>
To: "INCIDENTS (E-mail)" <INCIDENTS@SECURITYFOCUS.COM>

I vaguely remember seeing something about this a month or so ago, but I
don't remember any details. I am getting attempts 1-2 times a day from
different IP addresses on TCP port 22.

nmap returns this:

Port State Protocol Service
21 open tcp ftp
22 open tcp ssh
23 open tcp telnet
80 filtered tcp http
5001 open tcp commplex-link

I can't get a telnet, or http response, but ssh and ftp do. FTP - (not
trying to log in, just getting the headers) shows:

220 ArrowPoint (5.3.1) FTP server ready
Name (216.34.77.12:root):
331 Password required
Password:
530 Login failed.
Login failed.
ftp> quit
221 Thank you for visiting. May the remainder of your day be filled with
joy.

I also can't find any good info on the port 5001, I'm assuming these
systems have been compromised, but I'd like to make sure before I start
trying to contact anyone.

Thanks

Chad Mawson
Woods & Aitken LLP

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com



Relevant Pages

  • Help: FTP over SSH to Windows FTP server behind Linux gateway/firewall
    ... How do I encrypt a regular ftp session over SSH with the following ... rp: = remote port: ...
    (comp.security.ssh)
  • Re: ssh scans
    ... There are a couple of well known holes in the CSS (nee ArrowPoint). ... >Port 5001 is the default port for the Application Peering Protocol. ... >> I can't get a telnet, or http response, but ssh and ftp do. ... >> and tracking system please see: http://aris.securityfocus.com ...
    (Incidents)
  • Re: tunnelling
    ... > If I want to tunnel a ftp connection I have to ... > server I want to connect to, port 21. ... What you're doing is telling your SSH client to _listen_ on port 21 ...
    (comp.security.ssh)
  • Re: ftp server question
    ... That innocent looking port scan you see in your firewall today could ... So anyone running an open FTP server has probably already been 'found out' but not everyone runs a log and even fewer probably check it! ... the SSH server, so it only gets attacked once every three minutes tops. ...
    (alt.computer.security)
  • RE: FTPD & SSHD server
    ... I think you are confused about difference between ssh and FTPD. ... This FTP software gives FTP protocol ... not used over the public internet. ... high port number for data channel in passive mode. ...
    (freebsd-questions)