Educause Security Discussion mailing list archives

Re: Ongoing distributed Linux SSH dictionary attack


From: Pete Hickey <pete () SHADOWS UOTTAWA CA>
Date: Thu, 16 Apr 2009 19:59:06 -0400

On Thu, Apr 16, 2009 at 04:15:00PM -0700, Andrew Daviel wrote:
FYI

We are seeing a distributed-source SSH dictionary attack on multiple
machines. The sources appear to be running Linux according to P0F. This
blows past our "15 strikes sitewide and you are out" filter.

We're seeing a large increase of ssh dictionary attacks this week.  Although
it's coming from a number of different machines, I wouldn't call it a large
enough number to consider it a distributed attack.

--
Pete Hickey                         What started out as innocent
The University of Ottawa            environmentalist tree-hugging
Ottawa, Ontario                     progressed to lewd acts with
Canada                              rhododendrons.

Current thread: