Gentoo Archives: gentoo-security

From: Mark Guertin <guertin@××××××××××××××.com>
To: gentoo-security@l.g.o
Subject: Re: [gentoo-security] new ssh worm?
Date: Tue, 27 Jul 2004 17:20:51
Message-Id: 2F9CF1CF-DFF1-11D8-B3DF-000A95DC1AB2@brucemaudesign.com
In Reply to: [gentoo-security] new ssh worm? by Greg Watson
1 Yep I've seen the same thing on my machines here over the last 2-3 days
2 or so, on accounts test and guest.
3
4 Unfortunately we all don't have the option to turn off interactive
5 logins, so hopefully this is not something that will get out of hand :/
6
7 Mark
8
9 On 27-Jul-04, at 12:30 PM, Greg Watson wrote:
10
11 > -----BEGIN PGP SIGNED MESSAGE-----
12 > Hash: SHA1
13 >
14 > Over the past few days I've noticed many attempts from different
15 > sources
16 > trying to login on ssh via guest/test/admin/etc accounts. Looking
17 > further into the matter I found SANS is looking for information too.
18 >
19 > http://www.incidents.org/diary.php?date=2004-07-23
20 > http://www.incidents.org/diary.php?date=2004-07-25
21 >
22 > and more information here:
23 > http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999
24 >
25 > It appears as the net is getting hit with these all over. I would
26 > guess
27 > this is a very early stage of some kind of new worm/exploit in the
28 > works. What is more, it appears to have the ability to pass some NAT
29 > boxes by tricking them into replying back to the source.
30 >
31 > If you're not already doing so, I recommend to disable password
32 > interactive login and enforce key only logins. This will prevent some
33 > of the ssh exploits, brute-force attacks, and general script kiddies.
34 >
35 > And as always, upgrade to the latest version of OpenSSH/OpenSSL.
36 > - --
37 > Greg Watson
38 > http://www.linuxlogin.com
39 > GnuPG Key: http://www.linuxlogin.com/gpg_key.pub
40 > -----BEGIN PGP SIGNATURE-----
41 > Version: GnuPG v1.2.4 (GNU/Linux)
42 > Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
43 >
44 > iD8DBQFBBoMk0stmTYtmfxsRAgEtAJ4xX4NUhVY1TrQ2sLVw2VOH3/02KACgiOak
45 > 7fJRiR57F4RbRZQflDbIVqs=
46 > =r4zY
47 > -----END PGP SIGNATURE-----
48 >
49 > --
50 > gentoo-security@g.o mailing list
51 >
52 >
53
54
55 --
56 gentoo-security@g.o mailing list