Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Incidents
SSH attacks? Jul 26 2004 10:59PM
Robin (robin kallisti net nz) (10 replies)
Re: SSH attacks? Jul 29 2004 10:31AM
David Block (dave yucc yorku ca)
Re: SSH attacks? Jul 28 2004 04:33AM
brandy (brandy klammeraffe org) (2 replies)
Re: SSH attacks? Jul 29 2004 12:22AM
Andrew J Caines (A J Caines halplant com) (3 replies)
Re: SSH attacks? Jul 29 2004 10:12PM
Brian C. Lane (bcl brianlane com)
RE: SSH attacks? Jul 29 2004 06:32PM
Herman Frederick Ebeling Jr. (hfebelingjr lycos com)
Re: SSH attacks? Jul 29 2004 05:22PM
Marcus Merrin (marcus merrin emptyair com) (1 replies)
Re: SSH attacks? Jul 30 2004 12:58AM
Robin (robin kallisti net nz)
Re: SSH attacks? Jul 29 2004 12:18AM
Mike Whitley (mwhitley borg proceon com)
Re: SSH attacks? Jul 27 2004 09:12PM
buzz (reitenba fh-brandenburg de) (2 replies)
Re: SSH attacks? Jul 28 2004 07:05PM
Jyri Hovila (jyri hovila iki fi) (4 replies)
Re: SSH attacks? Jul 30 2004 05:40AM
Thomas Hochstein (ml ancalagon inka de)
Re: SSH attacks? Jul 29 2004 07:03PM
Chris Brenton (cbrenton chrisbrenton org)
On Wed, 2004-07-28 at 15:05, Jyri Hovila wrote:
>
> It seems that at least one host has been rooted somehow relating to the
> scans we're seeing:
>
> http://www.dslreports.com/forum/remark,10854834~mode=flat~days=9999~star
t=60

More than just one. I'm willing to bet every source IP that hits you was
compromised the same way.

One interesting tid bit I've noticed is that every source IP I've
checked had SQL listening. Not sure if its related or a coincidence.

> I'm pretty sure there is a new SSH exploit around. At least this clearly
> isn't a brute force attack.

I guess I don't see how you are drawing that conclusion. To quote from
the link you provided above:

[QUOTE]
Jul 12 22:26:51 server sshd[12868]: Accepted password for test from
130.15.15.239 port 1954 ssh2
Jul 12 22:42:35 server sshd[13998]: Accepted password for test from
216.55.164.10 port 56454 ssh2
[/QUOTE]

IMHO this *is not* an exploit, but rather a connection due to a poor
password policy for the user "test" (in other words, this is classic
brute force). You could be running an outdated SSH version, use good
passwords, and be totally safe from this type of attack (not that I'm
advocating running outdated software, just trying to make a point).

> As we are seeing lots of scans, but only few
> rooted hosts, it really doesn't look like a worm either. Someone seems
> to be scanning for vulnerable SSH daemons, obviously using previously
> rooted hosts, and then roots vulnerable hosts of his/her choice
> manually.

Based on the info I've seen, I believe the brute force portion is
automated while the actual toolkit install and "rooting" is being done
manually. It looks too much like a newbie fumbling around.

> As I wrote in my previous message, I think it's a good choise to limit
> access to SSH until this issue is solved.

Always a good idea, but if it was me I would grab a copy of John The
Ripper, the passwd & shadow files, and ensure you are using decent
password on all of your accounts.

HTH,
Chris

[ reply ]
Re: SSH attacks? Jul 29 2004 05:03PM
Matt Beland (matt rearviewmirror org)
Re: SSH attacks? Jul 29 2004 05:02PM
Valdis Kletnieks vt edu
Re: SSH attacks? Jul 28 2004 06:42PM
Jyri Hovila (jyri hovila iki fi)
Re: SSH attacks? Jul 27 2004 08:46PM
Adam Young (adam vbfx com) (1 replies)
Re: SSH attacks? Jul 28 2004 08:19AM
Christine Kronberg (Christine_Kronberg genua de) (3 replies)
Re: SSH attacks? Jul 29 2004 04:53PM
Steve Schuster (sjs74 cornell edu)
Re: SSH attacks? Jul 29 2004 04:05PM
Merlijn Tishauser (merlijn begeleidingentraining nl)
Re: SSH attacks? Jul 29 2004 09:21AM
Pieter-Bas IJdens (pieter-bas ijdens com) (2 replies)
Re: SSH attacks? Jul 30 2004 12:38AM
Jay D. Dyson (jdyson treachery net) (2 replies)
Re: SSH attacks? Jul 31 2004 12:06AM
mgotts 2roads com
Re: SSH attacks? Jul 31 2004 12:05AM
Frank Knobbe (frank knobbe us)
Re: SSH attacks? Jul 29 2004 10:12AM
Christine Kronberg (Christine_Kronberg genua de) (2 replies)
Re: SSH attacks? Jul 30 2004 01:26AM
Frank Knobbe (frank knobbe us)
Re: SSH attacks? Jul 29 2004 10:44AM
Pieter-Bas IJdens (pieter-bas ijdens com)
Re: SSH attacks? Jul 27 2004 07:21PM
Tom Laermans (tom laermans powersource cx)
Re: SSH attacks? Jul 27 2004 07:17PM
Chris Brown (chris wavetex com)
Re: SSH attacks? Jul 27 2004 06:24PM
Jason Falciola (falciola us ibm com)
Re: SSH attacks? Jul 27 2004 06:15PM
Paul Schmehl (pauls utdallas edu) (1 replies)
Re: SSH attacks? Jul 30 2004 06:37PM
George Georgalis (george galis org)
Re: SSH attacks? Jul 27 2004 06:06PM
Josh Tolley (josh raintreeinc com)
Re: SSH attacks? Jul 27 2004 06:00PM
Tobias Rice (rice up edu) (1 replies)
Re: SSH attacks? Jul 28 2004 03:43AM
Chris Brenton (cbrenton chrisbrenton org)







 

Privacy Statement
Copyright 2009, SecurityFocus