Re: SSH scans...

From: Dejan Markovic (dejanmarkovic_at_hotmail.com)
Date: 12/22/04

  • Next message: nixsec: "Re: SSH scans..."
    To: "nixsec" <nixsec@area66.org>
    Date: Wed, 22 Dec 2004 10:15:46 -0500
    
    

    Hi Paulo,

    Just replied to Brian, he wrote a code called timelox, it's been posted on
    the list, I'll check it out later when I get a chance, but seems to do just
    that. Talk to you later. Thanks,

    Regards,
    Dan

    ----- Original Message -----
    From: "nixsec" <nixsec@area66.org>
    To: "Dejan Markovic" <dejanmarkovic@hotmail.com>
    Cc: <INCIDENTS@securityfocus.com>
    Sent: Tuesday, December 21, 2004 5:46 PM
    Subject: Re: SSH scans...

    I have gotten these attacks before and did some research on it, its a
    SSH bruteforce program released a few months ago that can be located at:
    http://www.k-otik.com/exploits/08202004.brutessh2.c.php

    Something that would be nice is some feature in ssh that would only
    allow 3 login atempts from 1 IP, if they get it wrong 3 times to
    automaticly block any connections from that ip.

    Paulo Ferreira.

    Dejan Markovic wrote:

    >Hi Guys,
    >
    >Don't know whether this is the right list, but need to ask if others have
    >the same entries in their logs for the past number of months. Let me take a
    >step back, I maintain a number of networks on different IP ranges and they
    >are all being probed by what looks like a tool, or maybe it is the same
    >group/script. The originating computers range from open proxies to owned
    >boxes and there are two distinct patterns I've seen so far. The following
    >scan is a recent example where the root/password from x.x.x.x: 59 Time(s)
    >caught my attention the first time a while back, and still getting the same
    >scans on a daily basis:
    >
    >account/password from 210.245.168.28: 1 Time(s)
    >adam/password from 210.245.168.28: 1 Time(s)
    >adm/password from 210.245.168.28: 2 Time(s)
    >alan/password from 210.245.168.28: 1 Time(s)
    >apache/password from 210.245.168.28: 1 Time(s)
    >backup/password from 210.245.168.28: 1 Time(s)
    >cip51/password from 210.245.168.28: 1 Time(s)
    >cip52/password from 210.245.168.28: 1 Time(s)
    >cosmin/password from 210.245.168.28: 1 Time(s)
    >cyrus/password from 210.245.168.28: 1 Time(s)
    >data/password from 210.245.168.28: 1 Time(s)
    >frank/password from 210.245.168.28: 1 Time(s)
    >george/password from 210.245.168.28: 1 Time(s)
    >henry/password from 210.245.168.28: 1 Time(s)
    >horde/password from 210.245.168.28: 1 Time(s)
    >iceuser/password from 210.245.168.28: 1 Time(s)
    >irc/password from 210.245.168.28: 2 Time(s)
    >jane/password from 210.245.168.28: 1 Time(s)
    >john/password from 210.245.168.28: 1 Time(s)
    >master/password from 210.245.168.28: 1 Time(s)
    >matt/password from 210.245.168.28: 1 Time(s)
    >mysql/password from 210.245.168.28: 1 Time(s)
    >nobody/password from 210.245.168.28: 1 Time(s)
    >noc/password from 210.245.168.28: 1 Time(s)
    >operator/password from 210.245.168.28: 1 Time(s)
    >oracle/password from 210.245.168.28: 1 Time(s)
    >pamela/password from 210.245.168.28: 1 Time(s)
    >patrick/password from 210.245.168.28: 2 Time(s)
    >rolo/password from 210.245.168.28: 1 Time(s)
    >root/password from 210.245.168.28: 59 Time(s)
    >server/password from 210.245.168.28: 1 Time(s)
    >sybase/password from 210.245.168.28: 1 Time(s)
    >test/password from 210.245.168.28: 5 Time(s)
    >user/password from 210.245.168.28: 3 Time(s)
    >web/password from 210.245.168.28: 2 Time(s)
    >webmaster/password from 210.245.168.28: 1 Time(s)
    >www-data/password from 210.245.168.28: 1 Time(s)
    >www/password from 210.245.168.28: 1 Time(s)
    >wwwrun/password from 210.245.168.28: 1 Time(s)
    >
    >Regards,
    >Dan
    >
    >
    >
    >


  • Next message: nixsec: "Re: SSH scans..."

    Relevant Pages

    • Re: postponed *and* interrupted composition
      ... there's a first time for everyone. ... you ssh in, 'screen -r' will reattach to the previous session iff the ... remote machine has not been rebooted. ... Donna Rosa, toccata da divina luce, ...
      (comp.mail.pine)
    • Re: [opensuse] Clueless about SSH
      ... and try scp and ssh again. ... recreated the first time the foreign connection is made the next time.. ... known_hosts blah, blah, blah... ...
      (SuSE)
    • Re: can openssh/logins be exploited this way?
      ... maybe i didnt quite explain the dyndns problem. ... saved into my known hosts, ... > As far as SSH is concerned, the point here is that you shouldn't have done ... When you connected for the first time to ...
      (comp.security.ssh)
    • Re: warning: remote host identification has changed!
      ... Todd H. schrieb: ... really a man-in-the-middle attack? ... and created a new ssh key and root password. ... But what about the chance that the forged key has the same fingerprint than mine? ...
      (comp.security.ssh)
    • Re: CD-blanking leads to machine freeze with current -git [was: Re: CD writing in future Lin
      ... ssh into the box and then try to blank the CD on the local machine. ... My guess is that your burner and hard drive are both on the same ide channel, and so you can not access the disk while the burner is blanking. ... I've been waiting 30 minutes for the machine to come back but no chance. ...
      (Linux-Kernel)