1 |
On Thu, Mar 19, 2009 at 10:19:37AM -0500, Paul Hartman wrote: |
2 |
> |
3 |
> In my ssh logs this morning I noticed a couple login attempts with |
4 |
> usenames on them... I've never seen that before. It is usually just an |
5 |
> IP address. |
6 |
> |
7 |
> Mar 18 20:19:48 [sshd] refused connect from postmaster@×××××××××××××××××××.co |
8 |
> Mar 18 23:42:44 [sshd] refused connect from 211.116.136.107 |
9 |
> Mar 18 23:44:44 [sshd] refused connect from |
10 |
> [U2FsdGVkX19g32YZVKMsQkl+mouWITILOicY4Iq9OQo=]@211.116.136.107 |
11 |
> Mar 19 02:41:09 [sshd] refused connect from 221.194.128.66 |
12 |
> |
13 |
> weird... maybe the bad guys are up to something new. |
14 |
|
15 |
It could be a try to a format string vulnerability or just a bot doing |
16 |
stupid and irrelevant things. I think you should ask to the guys on the |
17 |
openssh project. |
18 |
|
19 |
-- |
20 |
Nicolas Sebrecht |