Re: Suspicious Log Entry

From: marko (chrome_at_liquidNOS_PAMinfo.net)
Date: 10/28/03


Date: Tue, 28 Oct 2003 10:25:24 +0200

On Wed, 22 Oct 2003 13:25:09 GMT
"Buck Turgidson" <jc_va@hotmail.com> wrote:

> Could this indicate someone trying to ssh into my linux server?
> Oct 21 06:04:06 hp sshd[20947]: Did not receive identification string
> from ::ffff:211.162.62.3

As you stated in the thread, someone dropped the connection. Most
probably it was someone portscanning/banner-grabbing ssh-servers with an
automated scanner, looking for vulnerable systems.

Your ssh-version appears to be quite old, btw ;-) 3.7.1 is current,
check the last entries at http://www.openssh.org/security.html

-m-

-- 
- Liquid Information - http://www.liquidinfo.net
- E-mail: Remove NOS_PAM if present in address (Usenet)
- PGP: http://www.liquidinfo.net/about.html
--