Re: Internet SSH scans




On Thursday 02 March 2006 18:08, Alexandre H wrote:
Hi,

I've witnessed what I think is an increase in SSH scans over the
Internet in the past four or five weeks. The scan seems to originate
from various countries around the globe which makes me think of it to be
a worm-like spreading virus searching for vulnerable systems running the
SSH service. I confirmed the attack with a friend of mine who also
happens to run a SSH server at home. We both live in Montreal, QC,
Canada and are using the same ISP.

We see such dictionary scans once or twice a week in any given network that
we monitor. We have not noticed an _increase_ however.

A combination of tight sshd_config settings, pam_tally, and connection rate
throttling on the firewall are useful mitigation methods.

We were recently asked to investigate a server which was successfully
compromised by such a scan. The scan originated in 4 countries
(2 of these _might_ be a coincidence), and the tool does not stop when
it succeeds, instead it seems to log the results on the attacking machine
which is then post-processed. The intruder quickly set up a backdoored
sshd, an ssh scanner (presumably the same one that they were using),
and proceeded to set up a phishing email generator.



Skip


--
Dr. Everett (Skip) Carter Phone: 831-641-0645 FAX: 831-641-0647
Taygeta Network Security Services email: skip@xxxxxxxxxxx
1340 Munras Ave., Suite 314 WWW: http://www.taygeta.net/
Monterey, CA. 93940



Relevant Pages

  • Re: Safest way of accessing a home computer from outside?
    ... what if I my router doesent have a public IP ... use for ssh is forwarded to your ssh server. ... You can find Hamachi at ...
    (Fedora)
  • Re: Safest way of accessing a home computer from outside?
    ... what if I my router doesent have a public IP ... I agree - ssh with no password and then use certificates to ... use for ssh is forwarded to your ssh server. ... You can find Hamachi at ...
    (Fedora)
  • Re: AIX 5.2L "who" question
    ... SSH is corrupting the utmp file! ... where did you get the SSH server you are running? ... We have a 44P-270 running AIX 5.2L, when users connected via ssh they can't ... Monitoring ...
    (AIX-L)
  • Re: Blocking attacks from spoofed IP addresses
    ... Some of the ssh attacks are distributed. ... So IMHO public key authentication does not necessarily reduce risks. ... if one is scared about login unwanted attempts on a ssh server ...
    (comp.os.linux.networking)
  • Re: Remote Desktop from Linux console
    ... if your running a SSH server on L you can connect to V using RDC through the SSH tunnel. ... I do, or did, that all the time when I ran a SSH server on either a PC inside my router or on the router itself, ie. DD-WRT running on the router. ...
    (microsoft.public.windows.vista.networking_sharing)

Quantcast