Security Basics mailing list archives

SSH connection attempts in logs.


From: "Nick Vaernhoej" <nick.vaernhoej () capitalcardservices com>
Date: Mon, 24 Sep 2007 16:36:37 -0500

Good afternoon,

I am finding some entries in our firewall logs that I think are odd.

Connections are initiated on port 22 and closed on port 0

Can anyone enlighten me? I lean towards it being internet noise but
couldn't help wondering.

xxx.xxx.xxx.xxx = them
yyy.yyy.yyy.yyy = me

c=262144 m=98 msg="Connection Opened" n=187596
src=xxx.xxx.xxx.xxx:32881:X1 dst=yyy.yyy.yyy.yyy:22:X1 proto=tcp/22
c=1024 m=537 msg="Connection Closed" n=139129
src=xxx.xxx.xxx.xxx:32881:X1 dst=yyy.yyy.yyy.yyy:0:X1 proto=tcp/0

Thank you

Nick Vaernhoej
"Quidquid latine dictum sit, altum sonatur."


This electronic transmission is intended for the addressee (s) named above. It contains information that is privileged, 
confidential, or otherwise protected from use and disclosure. If you are not the intended recipient you are hereby 
notified that any review, disclosure, copy, or dissemination of this transmission or the taking of any action in 
reliance on its contents, or other use is strictly prohibited. If you have received this transmission in error, please 
notify the sender that this message was received in error and then delete this message.
Thank you.


Current thread: