Gentoo Archives: gentoo-user

From: Nicolas Sebrecht <nicolas.s-dev@×××××××.net>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: Usernames in ssh attacks
Date: Thu, 19 Mar 2009 19:01:25
Message-Id: 20090319190122.GA18710@vidovic
In Reply to: [gentoo-user] Usernames in ssh attacks by Paul Hartman
1 On Thu, Mar 19, 2009 at 10:19:37AM -0500, Paul Hartman wrote:
2 >
3 > In my ssh logs this morning I noticed a couple login attempts with
4 > usenames on them... I've never seen that before. It is usually just an
5 > IP address.
6 >
7 > Mar 18 20:19:48 [sshd] refused connect from postmaster@×××××××××××××××××××.co
8 > Mar 18 23:42:44 [sshd] refused connect from 211.116.136.107
9 > Mar 18 23:44:44 [sshd] refused connect from
10 > [U2FsdGVkX19g32YZVKMsQkl+mouWITILOicY4Iq9OQo=]@211.116.136.107
11 > Mar 19 02:41:09 [sshd] refused connect from 221.194.128.66
12 >
13 > weird... maybe the bad guys are up to something new.
14
15 It could be a try to a format string vulnerability or just a bot doing
16 stupid and irrelevant things. I think you should ask to the guys on the
17 openssh project.
18
19 --
20 Nicolas Sebrecht