1 |
Noticed the same here myself, running a server on a home IP range, wasn't |
2 |
expecting anything but there is :/ |
3 |
|
4 |
>From various hosts, various logins tried (and failed). Hope it doesn't |
5 |
cause too many issues |
6 |
|
7 |
Tim |
8 |
|
9 |
> -----BEGIN PGP SIGNED MESSAGE----- |
10 |
> Hash: SHA1 |
11 |
> |
12 |
> Over the past few days I've noticed many attempts from different sources |
13 |
> trying to login on ssh via guest/test/admin/etc accounts. Looking |
14 |
> further into the matter I found SANS is looking for information too. |
15 |
> |
16 |
> http://www.incidents.org/diary.php?date=2004-07-23 |
17 |
> http://www.incidents.org/diary.php?date=2004-07-25 |
18 |
> |
19 |
> and more information here: |
20 |
> http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999 |
21 |
> |
22 |
> It appears as the net is getting hit with these all over. I would guess |
23 |
> this is a very early stage of some kind of new worm/exploit in the |
24 |
> works. What is more, it appears to have the ability to pass some NAT |
25 |
> boxes by tricking them into replying back to the source. |
26 |
> |
27 |
> If you're not already doing so, I recommend to disable password |
28 |
> interactive login and enforce key only logins. This will prevent some |
29 |
> of the ssh exploits, brute-force attacks, and general script kiddies. |
30 |
> |
31 |
> And as always, upgrade to the latest version of OpenSSH/OpenSSL. |
32 |
> - -- |
33 |
> Greg Watson |
34 |
> http://www.linuxlogin.com |
35 |
> GnuPG Key: http://www.linuxlogin.com/gpg_key.pub |
36 |
> -----BEGIN PGP SIGNATURE----- |
37 |
> Version: GnuPG v1.2.4 (GNU/Linux) |
38 |
> Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org |
39 |
> |
40 |
> iD8DBQFBBoMk0stmTYtmfxsRAgEtAJ4xX4NUhVY1TrQ2sLVw2VOH3/02KACgiOak |
41 |
> 7fJRiR57F4RbRZQflDbIVqs= |
42 |
> =r4zY |
43 |
> -----END PGP SIGNATURE----- |
44 |
> |
45 |
> -- |
46 |
> gentoo-security@g.o mailing list |
47 |
> |
48 |
> |
49 |
|
50 |
|
51 |
|
52 |
-- |
53 |
gentoo-security@g.o mailing list |