1 |
I've noticed this as well...is it just an sshd.conf entry to diable |
2 |
password interactive logins? |
3 |
|
4 |
|
5 |
|
6 |
-----Original Message----- |
7 |
From: Greg Watson [mailto:gwatson@××××××××××.com] |
8 |
Sent: Tuesday, July 27, 2004 12:31 PM |
9 |
To: gentoo-security@l.g.o |
10 |
Subject: [gentoo-security] new ssh worm? |
11 |
|
12 |
|
13 |
-----BEGIN PGP SIGNED MESSAGE----- |
14 |
Hash: SHA1 |
15 |
|
16 |
Over the past few days I've noticed many attempts from different sources |
17 |
trying to login on ssh via guest/test/admin/etc accounts. Looking |
18 |
further into the matter I found SANS is looking for information too. |
19 |
|
20 |
http://www.incidents.org/diary.php?date=2004-07-23 |
21 |
http://www.incidents.org/diary.php?date=2004-07-25 |
22 |
|
23 |
and more information here: |
24 |
http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999 |
25 |
|
26 |
It appears as the net is getting hit with these all over. I would guess |
27 |
this is a very early stage of some kind of new worm/exploit in the |
28 |
works. What is more, it appears to have the ability to pass some NAT |
29 |
boxes by tricking them into replying back to the source. |
30 |
|
31 |
If you're not already doing so, I recommend to disable password |
32 |
interactive login and enforce key only logins. This will prevent some |
33 |
of the ssh exploits, brute-force attacks, and general script kiddies. |
34 |
|
35 |
And as always, upgrade to the latest version of OpenSSH/OpenSSL. |
36 |
- -- |
37 |
Greg Watson |
38 |
http://www.linuxlogin.com |
39 |
GnuPG Key: http://www.linuxlogin.com/gpg_key.pub |
40 |
-----BEGIN PGP SIGNATURE----- |
41 |
Version: GnuPG v1.2.4 (GNU/Linux) |
42 |
Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org |
43 |
|
44 |
iD8DBQFBBoMk0stmTYtmfxsRAgEtAJ4xX4NUhVY1TrQ2sLVw2VOH3/02KACgiOak |
45 |
7fJRiR57F4RbRZQflDbIVqs= |
46 |
=r4zY |
47 |
-----END PGP SIGNATURE----- |
48 |
|
49 |
-- |
50 |
gentoo-security@g.o mailing list |
51 |
|
52 |
|
53 |
-- |
54 |
gentoo-security@g.o mailing list |