Re: Port 22 SNAFU? Help!

From: Darren Dunham (ddunham_at_redwood.taos.com)
Date: 08/17/05


Date: Wed, 17 Aug 2005 20:16:41 GMT

MikesBrain <Mike@n.uk> wrote:

> ssh from P1 to P2 connects without a problem even if port
> 22 is dropped by the firewall, even with the #x# hashed-out
> lines that should (in theory anyway) DROP a connect request
> on port 22.

> Therefore, logically, ssh is NOT using port 22, even though
> it is specified in the config file.

Can you just verify that?

>From P1, do 'telnet P2 22' and see if you get an SSH banner.

If that doesn't work, I'd snoop/tcpdump from the client and server and
see what ports are being used.

-- 
Darren Dunham                                           ddunham@taos.com
Senior Technical Consultant         TAOS            http://www.taos.com/
Got some Dr Pepper?                           San Francisco, CA bay area
         < This line left intentionally blank to confuse you. >


Relevant Pages

  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (NT-Bugtraq)
  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (Incidents)
  • RE: NT Compromise
    ... TCP port 6667 and 6668 are used for IRC. ... to this it seems that your server might have connection to one of IRC ... Subject: NT Compromise ... has timed out a request to STEELSRV. ...
    (Incidents)
  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (Bugtraq)
  • Malicious use of grc.com
    ... ShieldsUpis an application developed by Steve Gibson of Gibson ... Research Corporation that allows a web user to request a remote port scan ... ShieldsUp happily scans the other box while returning the result set into ...
    (Focus-Microsoft)