Security Incidents mailing list archives
Re: RE: Internet SSH scans
From: Daxomatic <nerden () gmail com>
Date: Fri, 3 Mar 2006 16:06:05 +0100
Hi List, like anybody on the net i have these problems too, and was bored with scrolling the endless logs. So i decided to put an end to it. Here is a (rather small but effective and a bit blunt )script to put a stop to this annoying behaviour ;-p #!/bin/bash tail -0f /var/adm/messages |while read line; do echo "$line"|awk '/Invalid user/ {printf ("block in quick on bge1 proto tcp from %s to any port = 22 keep state\n",$NF)}' |ipf -f -; done as you all can see this is for a solaris 10 box (ipf) if you want to make it work for linux you could do something like this this; tail -0f /var/log/messages |while read line; do echo $line|awk '/Invalid user/{printf $NF}' |cut -b 8-|xargs -i iptables -A INPUT -p tcp -m multiport --destination-ports 22 -s {} -j DROP; done I know there are better ways to script this but hey, its quick and it works for me so perhaps its usefull for you guys/girls too :-) Rgds Dax Hoes On 3 Mar 2006 05:14:44 -0000, admin () chem uw edu pl <admin () chem uw edu pl> wrote:
I have many SSH scans in my large academic network. IMO scanning hosts are Windows zombies. /p
Current thread:
- RE: Internet SSH scans, (continued)
- RE: Internet SSH scans terry white (Mar 03)
- Re: Internet SSH scans Jonathan Nichols (Mar 03)
- RE: Internet SSH scans terry white (Mar 03)
- Re: Internet SSH scans Skip Carter (Mar 03)
- Re: Internet SSH scans Daniel Cid (Mar 03)
- Message not available
- Re: Internet SSH scans Jamie Riden (Mar 03)
- Re: Internet SSH scans Matt Rae (Mar 03)
- Re: Internet SSH scans Hugo J. Curti (Mar 06)
- RE: Internet SSH scans steve (Mar 02)
- RE: Internet SSH scans Peter Bassill (Mar 03)
- Re: RE: Internet SSH scans admin (Mar 03)
- Re: RE: Internet SSH scans Daxomatic (Mar 03)
- Re: RE: Internet SSH scans Christine Kronberg (Mar 03)
- Re: Internet SSH scans JK Adams (Mar 03)
- Re: RE: Internet SSH scans joakim . berge (Mar 03)
- Re: Re: RE: Internet SSH scans mrbits (Mar 03)
- RE: Internet SSH scans Adriano Carvalho (Mar 21)
- Re: Internet SSH scans Valdis . Kletnieks (Mar 22)
- Re: Internet SSH scans Adriano Carvalho (Mar 22)
- RE: Internet SSH scans Adriano Carvalho (Mar 21)
- Re: Internet SSH scans ilaiy (Mar 03)
- Re: Internet SSH scans Stephen J. Smoogen (Mar 03)