Re: SSH connections

From: Jani Mikkonen (jani_at_mikkonen.org)
Date: 08/29/05


Date: Mon, 29 Aug 2005 16:02:07 +0300


> Be advised that the nature of the attacks changes constantly. A couple of
> years ago I saw attacks limited to 3-4 standard Unixy accounts. Lately, I
> see what looks like a more evolved version of the same attacks--same Unixy
> accounts, but with the beginnings of a decent dictionary attack. I suspect
> it's an evolved version of the same tool because I see roughly the same
> distribution in attack sources. That's a very shaky assumption, but I've
> not had a need to chase it further.

Interesting part of these "evolving" scanners are that there seems to be
 this scanner that probes the sshd with certain accounts. As i have
multiple host up and running these scans happen pretty often but only
once ive seen a little bit of creativity in those scans.

The scanner had obviously identified the country where my host resides
and set the account dictionary accordingly and actually hit few correct
accounts with that scan of his/her.

99.9999% of the scans i get just use the same old same old account list.



Relevant Pages

  • Re: Protection from Hackers
    ... protect your hard drive from an intruder that had physical access to your ... protect the accounts in the domain from this sort of attack [though the ... Linux / Unix / BSD are also vulnerable to this sort of attack. ...
    (microsoft.public.win2000.security)
  • Re: ssh security
    ... what are valid accounts and what are not. ... It's considered axiomatic that security ... > system accounts (and over 99.9% are root, which does not get ssh access ... There are even some bots and apps that attack you from different IP ...
    (Fedora)
  • Re: Pubstro rash
    ... passwords against all of the accounts. ... We see this type of attack regularly in the .EDU world. ... administrator password on many machines, ... if there is a local administrative user named "brian" on that same ...
    (Incidents)
  • Re: TMNSP site attacked, back up
    ... > Due to an external attack, tmnsp.net has lost all users accounts ...
    (rec.music.gdead)
  • Re: physical security
    ... > Earlier I heard about that the offline Active Directory database attack is ... > possible and some tool is availabel to this attack. ... Any client you have will expose all it's local used accounts if a ...
    (microsoft.public.windows.server.active_directory)