Gentoo Archives: gentoo-hardened

From: atoth@××××××××××.hu
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Remote ssh attack: sshd tries to make udp connection to a remote host
Date: Sat, 29 Dec 2007 17:13:12
Message-Id: 33234.138.26.140.45.1198948261.squirrel@atoth.sote.hu
1 I've found a bunch of these messages in my log:
2 "grsec: From 219.87.17.209: (root:U:/usr/sbin/sshd) denied connect() to
3 219.87.17.3 port 0 sock type dgram protocol udp by /usr/sbin/sshd[sshd:19031]
4 uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/sshd[sshd:4997] uid/euid:0/0
5 gid/egid:0/0"
6 Along with these:
7 "Address 219.87.17.209 maps to cameo.com.tw, but this does not map back to
8 the
9 address - POSSIBLE BREAK-IN ATTEMPT!"
10
11 Is it a normal behavior of the sshd to make udp connections to remote
12 host? Especially using port 0? I have a feeling somebody could make my
13 sshd do bad things without grsec's RBAC system.
14
15 It annoys me. Are there anybody on the list with the same experience or
16 who knows more about this?
17
18 Regards,
19 Dw.
20 --
21 dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
22 Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
23
24 --
25 gentoo-hardened@g.o mailing list

Replies