Gentoo Archives: gentoo-security

From: Tim Igoe <tim@×××××××.uk>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] new ssh worm?
Date: Tue, 27 Jul 2004 17:50:51
Message-Id: 39125.195.137.39.206.1090954109.squirrel@195.137.39.206
In Reply to: [gentoo-security] new ssh worm? by Greg Watson
1 Noticed the same here myself, running a server on a home IP range, wasn't
2 expecting anything but there is :/
3
4 >From various hosts, various logins tried (and failed). Hope it doesn't
5 cause too many issues
6
7 Tim
8
9 > -----BEGIN PGP SIGNED MESSAGE-----
10 > Hash: SHA1
11 >
12 > Over the past few days I've noticed many attempts from different sources
13 > trying to login on ssh via guest/test/admin/etc accounts. Looking
14 > further into the matter I found SANS is looking for information too.
15 >
16 > http://www.incidents.org/diary.php?date=2004-07-23
17 > http://www.incidents.org/diary.php?date=2004-07-25
18 >
19 > and more information here:
20 > http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999
21 >
22 > It appears as the net is getting hit with these all over. I would guess
23 > this is a very early stage of some kind of new worm/exploit in the
24 > works. What is more, it appears to have the ability to pass some NAT
25 > boxes by tricking them into replying back to the source.
26 >
27 > If you're not already doing so, I recommend to disable password
28 > interactive login and enforce key only logins. This will prevent some
29 > of the ssh exploits, brute-force attacks, and general script kiddies.
30 >
31 > And as always, upgrade to the latest version of OpenSSH/OpenSSL.
32 > - --
33 > Greg Watson
34 > http://www.linuxlogin.com
35 > GnuPG Key: http://www.linuxlogin.com/gpg_key.pub
36 > -----BEGIN PGP SIGNATURE-----
37 > Version: GnuPG v1.2.4 (GNU/Linux)
38 > Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
39 >
40 > iD8DBQFBBoMk0stmTYtmfxsRAgEtAJ4xX4NUhVY1TrQ2sLVw2VOH3/02KACgiOak
41 > 7fJRiR57F4RbRZQflDbIVqs=
42 > =r4zY
43 > -----END PGP SIGNATURE-----
44 >
45 > --
46 > gentoo-security@g.o mailing list
47 >
48 >
49
50
51
52 --
53 gentoo-security@g.o mailing list

Replies

Subject Author
Re: [gentoo-security] new ssh worm? Tobias Klausmann <klausman@××××××××××××.de>
Re: [gentoo-security] new ssh worm? Matthew Russell <mor22@××××××.uk>