Home page logo

fulldisclosure logo Full Disclosure mailing list archives

Re: Automated SSH login attempts?
From: Paul Schmehl <pauls () utdallas edu>
Date: Sun, 25 Jul 2004 20:49:41 -0500

--On Thursday, July 22, 2004 10:47 AM -0400 Jay Libove <libove () felines org> wrote:

Here are some log entries from my system:

Jul 15 10:01:34 panther6 sshd[8267]: Illegal user test from
Jul 15 10:01:34 panther6 sshd[8267]: Failed password for illegal user

We've been seeing these as well, and in every case we've notified the owners, they have mailed us back to let us know that the host had been rooted.

You would be doing the owners a big favor by notifying them that their host is probably compromised.

Paul Schmehl (pauls () utdallas edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member

Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]