Re: "Don't panic"?

From: Nico Kadel-Garcia (nkadel@bellatlantic.net)
Date: 01/31/02


From: "Nico Kadel-Garcia" <nkadel@bellatlantic.net>
Date: Thu, 31 Jan 2002 06:35:10 GMT


"Steve Snyder" <swsnyder@home.com> wrote in message
news:v7T58.10145$gW4.7108161@news1.rdc1.mi.home.com...
> Mike Iglesias wrote:
>
> > In article <m1lk7u0ls31.fsf@sys1.des.jhy.us.ml.com>,
> > Richard Silverman <res@des.jhy.us.ml.com> wrote:
> >>What "abuse" would you have him report? He has a box connected to the
> >>Internet, with an SSH server accepting connections from anywhere.
Someone
> >>connected to it, exchanged a few bytes according the SSH protocol, then
> >>disconnected. That's not abuse; it's what's supposed to happen.
> >
> > Well Richard, if you've been scanned almost 60 times this month (like
> > we have) by people looking for ssh servers on your network, you'd
> > report it too. It's kinda obvious that if you're seeing scans from
> > scanssh, someone is mapping sshd versions on your network. If you don't
> > know who it's from, I doubt it's friendly.
>
> If all (or most if my scans were from a single source I would complain to
> the admin of the source. Alas, the origins of the scans don't seem to
> follow a pattern. So who do I complain to?

The upstream connectivity to their IP addresses, the same as mail relay
attempts. It might be polite, it might not, but if someone is rattling the
door to my house I want to know who it is.



Relevant Pages

  • Re: "Dont panic"?
    ... with an SSH server accepting connections from anywhere. ... That's not abuse; ...
    (comp.security.ssh)
  • Re: "Dont panic"?
    ... >What "abuse" would you have him report? ... with an SSH server accepting connections from anywhere. ... That's not abuse; ...
    (comp.security.ssh)
  • Re: X11 forwarding over non X11 hop
    ... > The both connections are successfull. ... > Now i dont know how to set it up. ... But it looks like your ssh server on remoteX11Host is not configured to ... You should find a line like "X11Forwarding yes". ...
    (comp.security.ssh)
  • Re: ban host
    ... >Is it possible to ban say all connections from *.aol.com from connecting to ... If your SSH server supports tcpwrappers (OpenSSH does, ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • Re: TECH:Bally / Stern Sol. Power Supply
    ... One ground for the low voltage filter cap ground, ... paralleled ground connections between the SDB and rectifier board. ... these parallel wires are tied to the same place at both ends of the ... Not for single source supplies such as this. ...
    (rec.games.pinball)