Security Incidents mailing list archives

Re: SSH attacks?


From: Jyri Hovila <jyri.hovila () iki fi>
Date: Wed, 28 Jul 2004 22:05:24 +0300

Hi again!

It seems that at least one host has been rooted somehow relating to the
scans we're seeing:

http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999~start=60

I'm pretty sure there is a new SSH exploit around. At least this clearly
isn't a brute force attack. As we are seeing lots of scans, but only few
rooted hosts, it really doesn't look like a worm either. Someone seems
to be scanning for vulnerable SSH daemons, obviously using previously
rooted hosts, and then roots vulnerable hosts of his/her choice
manually.

As I wrote in my previous message, I think it's a good choise to limit
access to SSH until this issue is solved.

- Jyri



##################################################################
# This message has been checked for viruses using Qmail-Scanner. #
# http://www.turvamies.fi                                        #
##################################################################


Current thread: