Gentoo Archives: gentoo-security

From: "Molavi
To: Greg Watson <gwatson@××××××××××.com>, gentoo-security@l.g.o
Subject: RE: [gentoo-security] new ssh worm?
Date: Tue, 27 Jul 2004 16:37:50
Message-Id: 0029BBF62A1BA9489F249958385A95A00B7328@forum.gtri-ad.gatech.edu
1 I've noticed this as well...is it just an sshd.conf entry to diable
2 password interactive logins?
3
4
5
6 -----Original Message-----
7 From: Greg Watson [mailto:gwatson@××××××××××.com]
8 Sent: Tuesday, July 27, 2004 12:31 PM
9 To: gentoo-security@l.g.o
10 Subject: [gentoo-security] new ssh worm?
11
12
13 -----BEGIN PGP SIGNED MESSAGE-----
14 Hash: SHA1
15
16 Over the past few days I've noticed many attempts from different sources
17 trying to login on ssh via guest/test/admin/etc accounts. Looking
18 further into the matter I found SANS is looking for information too.
19
20 http://www.incidents.org/diary.php?date=2004-07-23
21 http://www.incidents.org/diary.php?date=2004-07-25
22
23 and more information here:
24 http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999
25
26 It appears as the net is getting hit with these all over. I would guess
27 this is a very early stage of some kind of new worm/exploit in the
28 works. What is more, it appears to have the ability to pass some NAT
29 boxes by tricking them into replying back to the source.
30
31 If you're not already doing so, I recommend to disable password
32 interactive login and enforce key only logins. This will prevent some
33 of the ssh exploits, brute-force attacks, and general script kiddies.
34
35 And as always, upgrade to the latest version of OpenSSH/OpenSSL.
36 - --
37 Greg Watson
38 http://www.linuxlogin.com
39 GnuPG Key: http://www.linuxlogin.com/gpg_key.pub
40 -----BEGIN PGP SIGNATURE-----
41 Version: GnuPG v1.2.4 (GNU/Linux)
42 Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org
43
44 iD8DBQFBBoMk0stmTYtmfxsRAgEtAJ4xX4NUhVY1TrQ2sLVw2VOH3/02KACgiOak
45 7fJRiR57F4RbRZQflDbIVqs=
46 =r4zY
47 -----END PGP SIGNATURE-----
48
49 --
50 gentoo-security@g.o mailing list
51
52
53 --
54 gentoo-security@g.o mailing list