Gentoo Archives: gentoo-hardened

From: Ned Ludd <solar@g.o>
To: gentoo-hardened@l.g.o
Subject: Re: [gentoo-hardened] Remote ssh attack: sshd tries to make udp connection to a remote host
Date: Sat, 29 Dec 2007 17:33:17
Message-Id: 1198949473.5119.0.camel@simple
In Reply to: [gentoo-hardened] Remote ssh attack: sshd tries to make udp connection to a remote host by atoth@atoth.sote.hu
1 For grsec policy related questions I suggest using the upstream
2 grsec mailing list.
3
4 On Sat, 2007-12-29 at 18:11 +0100, atoth@××××××××××.hu wrote:
5 > I've found a bunch of these messages in my log:
6 > "grsec: From 219.87.17.209: (root:U:/usr/sbin/sshd) denied connect() to
7 > 219.87.17.3 port 0 sock type dgram protocol udp by /usr/sbin/sshd[sshd:19031]
8 > uid/euid:0/0 gid/egid:0/0, parent /usr/sbin/sshd[sshd:4997] uid/euid:0/0
9 > gid/egid:0/0"
10 > Along with these:
11 > "Address 219.87.17.209 maps to cameo.com.tw, but this does not map back to
12 > the
13 > address - POSSIBLE BREAK-IN ATTEMPT!"
14 >
15 > Is it a normal behavior of the sshd to make udp connections to remote
16 > host? Especially using port 0? I have a feeling somebody could make my
17 > sshd do bad things without grsec's RBAC system.
18 >
19 > It annoys me. Are there anybody on the list with the same experience or
20 > who knows more about this?
21 >
22 > Regards,
23 > Dw.
24 > --
25 > dr Tóth Attila, Radiológus Szakorvos jelölt, 06-20-825-8057, 06-30-5962-962
26 > Attila Toth MD, Radiologist in Training, +36-20-825-8057, +36-30-5962-962
27 >
28
29 --
30 gentoo-hardened@g.o mailing list