Full Disclosure mailing list archives
Re: [VulnDiscuss] Re: Automated SSH login attempts?
From: RBabb <rob_mailing_lists () rbabb net>
Date: Mon, 26 Jul 2004 15:29:56 -0400
Paul Schmehl wrote:
--On Thursday, July 22, 2004 10:47 AM -0400 Jay Libove <libove () felines org> wrote:This makes me feel better. I thought it odd that so many machines were hitting my ssh server. I even blocked it at the firewall for a day or so. Is anyone talking on what the bot system was that allowed them to automate this? It seemed that as soon as 1 got it so did a whole bunch more so obviously people are distributing lists of IP's for potential SSH access.Here are some log entries from my system: Jul 15 10:01:34 panther6 sshd[8267]: Illegal user test from 62.67.45.4 Jul 15 10:01:34 panther6 sshd[8267]: Failed password for illegal userWe've been seeing these as well, and in every case we've notified the owners, they have mailed us back to let us know that the host had been rooted.You would be doing the owners a big favor by notifying them that their host is probably compromised.
I'm not real sure on who to contact for these machines, but here are all the ones that have hit me. Mostly seem to be Asian so far.
Jul 25 19:48:40 server sshd[55910]: Failed password for illegal user test from 212.4.172.123 port 56843 ssh2 Jul 25 19:48:42 server sshd[55915]: Failed password for illegal user guest from 212.4.172.123 port 56916 ssh2 Jul 25 20:37:19 server sshd[57221]: Failed password for illegal user test from 210.40.224.10 port 49738 ssh2 Jul 25 20:37:22 server sshd[57223]: Failed password for illegal user guest from 210.40.224.10 port 49756 ssh2
Jul 24 21:37:50 server sshd[21578]: Failed password for illegal user test from 218.244.240.195 port 58900 ssh2 Jul 24 21:37:53 server sshd[21580]: Failed password for illegal user guest from 218.244.240.195 port 58928 ssh2
Jul 22 18:23:36 server sshd[38184]: Failed password for illegal user test from 216.86.221.113 port 58012 ssh2 Jul 22 18:23:37 server sshd[38195]: Failed password for illegal user guest from 216.86.221.113 port 51509 ssh2
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Automated SSH login attempts? Jay Libove (Jul 25)
- Re: Automated SSH login attempts? Andrei Galca-Vasiliu (Jul 25)
- Re: Automated SSH login attempts? Neal O'Creat (Jul 30)
- Re: Automated SSH login attempts? Valdis . Kletnieks (Jul 30)
- Re: Automated SSH login attempts? Jan Muenther (Jul 31)
- Re: Automated SSH login attempts? Neal O'Creat (Jul 30)
- Re: Automated SSH login attempts? Andrei Galca-Vasiliu (Jul 25)
- Re: Automated SSH login attempts? Harry Hoffman (Jul 25)
- Re: Automated SSH login attempts? Andrew Farmer (Jul 25)
- Re: Automated SSH login attempts? Paul Mohr (Jul 25)
- Re: Automated SSH login attempts? Paul Schmehl (Jul 25)
- Re: [VulnDiscuss] Re: Automated SSH login attempts? RBabb (Jul 27)
- Re: [VulnDiscuss] Re: Automated SSH login attempts? Paul Schmehl (Jul 27)
- Re: [VulnDiscuss] Re: Automated SSH login attempts? RBabb (Jul 27)
- Re: Automated SSH login attempts? Andrei Galca-Vasiliu (Jul 25)
- Re: Automated SSH login attempts? Shafik Yaghmour (Jul 26)
- Re: Automated SSH login attempts? Alain Crespo (Jul 28)
- <Possible follow-ups>
- Re: Automated SSH login attempts? syrrus (Jul 25)
- Re: Automated SSH login attempts? Joe Hickory (Jul 27)
- Re: Automated SSH login attempts? Juan Carlos Navea (Jul 29)
- RE: Automated SSH login attempts? Todd Towles (Jul 29)
- Re: Automated SSH login attempts? Ali Campbell (Jul 29)
- Re: Automated SSH login attempts? Andrew Farmer (Jul 29)