Re: SSH scans...

From: Barrie Dempster (barrie_at_reboot-robot.net)
Date: 12/20/04

  • Next message: Tim Kennedy: "Re: [incidents] SSH scans..."
    To: incidents@securityfocus.com
    Date: Mon, 20 Dec 2004 16:23:02 +0000
    
    
    

    On Mon, 2004-12-20 at 10:21 -0500, Dejan Markovic wrote:
    > need to ask if others have
    > the same entries in their logs
    <snip>

    Yep ongoing SSH scanning using multiple SSH bruteforce type tools, this
    has been discussed extensively on most of the infosec mailing lists.

    ATM If you aren't seeing SSH bruteforce attempts in your logs then your
    SSH server is down :-P

    Google the user/pass combinations for more information eg..
    http://www.google.com/search?sourceid=mozclient&ie=utf-8&oe=utf-8&q=frank+george+password+ssh

    With Regards..
    Barrie Dempster (zeedo) - Fortiter et Strenue

      http://www.bsrf.org.uk

    [ gpg --recv-keys --keyserver www.keyserver.net 0x96025FD0 ]

    
    



  • Next message: Tim Kennedy: "Re: [incidents] SSH scans..."

    Relevant Pages

    • Re: SSH compiled with backdoor
      ... backdoor passwd into the ssh and wont show up in wtmp, ... ever he logs in as) invisible, so say u login with the username root and ... your use the global hidden passwd it will allow him on as root. ... the file that logs all the logins with time stamps and src ips is "dev/saux" ...
      (Incidents)
    • RE: How to display IP of ssh user in message?
      ... How to display IP of ssh user in message? ... - Have a warning banner enabled at log in. ... do a lastb and it logs it by, ...
      (RedHat)
    • Re: how to react on ssh attacks?
      ... > to view the logs. ... The huge amount of ssh probes that have been going on for the last year or ... enforced routine password changes and password selection rules since the ...
      (Fedora)
    • Re: [Full-disclosure] Distributed SSH username/password brute forceattack
      ... logs and killing this type of attack is to reconfigure your OpenSSH ... Although key-based logins are easier on your ... logs, they also generate the problem of transitive access to the server. ... Although you can control how the SSH server on your side works, ...
      (Full-Disclosure)
    • Re: Help -- Have I been rooted?
      ... I only allowed ssh, httpd, and ftp port forwarding to my ... machine for the past few days while I used a store bought router. ... I checked the router logs and was greeted by pages of stuff like this: ...
      (comp.os.linux.security)

  • Quantcast