Re: SSH scans...

From: Ben Nelson (lists_at_venom600.org)
Date: 12/20/04

  • Next message: Steve Kemp: "Re: SSH scans..."
    Date: Mon, 20 Dec 2004 14:48:11 -0700
    To: Raymond Lillard <rlillard@sonic.net>
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Raymond Lillard wrote:
    |
    | PS I'm curious, has anybody heard of these scans
    | compromising a machine, ever?

    Yes. A colleague of mine had a machine with SSH open to the world. A
    user account called 'test' with a password of 'test' was used in one of
    these scans to gain access (I have no idea why he had an account like
    that on the server in the first place... :0/). When the scan occured,
    whatever bot was being used to scan just noted the availability of the
    account. The account was then used several days later for an
    interactive login with what looked like a live person, who installed an
    IRC server and an FTP server (on non-privileged ports).

    - --Ben
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.6 (GNU/Linux)

    iD8DBQFBx0ib3cL8qXKvzcwRAqMBAJ4lIG8uZ3WoDbUk1r6qJY1XereCzACg38JU
    I9ZkbRR5xBlVIlCpFTtmom8=
    =v9Xn
    -----END PGP SIGNATURE-----


  • Next message: Steve Kemp: "Re: SSH scans..."

    Relevant Pages

    • Re: Re-Post - "the trust relationship between this workstation and the
      ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... Client computer must use STRICTLY the INTERNAL DNS server which can ... Attr: subschemaSubentry ...
      (microsoft.public.windows.server.active_directory)
    • Re: Same question, still no answer!!!
      ... Sounds then like we are all paying for a feature set only large companies ... The "proxy server" pc is actually an older box stuffed ... Expectation #1) keep the ethernet more or less as is. ... The kids account would be ...
      (microsoft.public.windowsxp.basics)
    • Re: Re-Post - "the trust relationship between this workstation and the
      ... "the trust relationship between this workstation and the primary domain ... only problem is adding a new user account on the station. ... This would be on the DNS server 172.20.100.2 ... Attr: subschemaSubentry ...
      (microsoft.public.windows.server.active_directory)
    • Sending email to mydomain.com
      ... server will appear as undeliverable. ... This happens because you are using the POP3 connector... ... an NDR when an account doesn't exist). ... >different from the user account names for the exchange ...
      (microsoft.public.windows.server.sbs)
    • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
      ... Everytime I attempt to login under Basic Authentication, ... IUSR_blah account. ... the anonymous user impersonated by the IIS Server is the ... > Event Viewer Security log. ...
      (microsoft.public.inetserver.iis.security)