Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [VulnDiscuss] Re: [Full-Disclosure] Automated SSH login attempts? |
|---|---|
| Date: | Mon, 26 Jul 2004 15:29:56 -0400 |
Paul Schmehl wrote:
--On Thursday, July 22, 2004 10:47 AM -0400 Jay Libove <libove@felines.org> wrote:This makes me feel better. I thought it odd that so many machines were hitting my ssh server. I even blocked it at the firewall for a day or so. Is anyone talking on what the bot system was that allowed them to automate this? It seemed that as soon as 1 got it so did a whole bunch more so obviously people are distributing lists of IP's for potential SSH access.
Here are some log entries from my system:
Jul 15 10:01:34 panther6 sshd[8267]: Illegal user test from 62.67.45.4 Jul 15 10:01:34 panther6 sshd[8267]: Failed password for illegal user
We've been seeing these as well, and in every case we've notified the owners, they have mailed us back to let us know that the host had been rooted.
You would be doing the owners a big favor by notifying them that their host is probably compromised.
| Previous by Date: | RE: [ok] [Full-Disclosure] Possible Virus/Trojan, Todd Towles |
|---|---|
| Next by Date: | Re: [ok] [Full-Disclosure] Possible Virus/Trojan, Valdis . Kletnieks |
| Previous by Thread: | Re: [Full-Disclosure] Automated SSH login attempts?, Paul Schmehl |
| Next by Thread: | Re: [VulnDiscuss] Re: [Full-Disclosure] Automated SSH login attempts?, Paul Schmehl |
| Indexes: | [Date] [Thread] [Top] [All Lists] |