Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Honeypots: Re: Displaying SSH password attempts

Re: Displaying SSH password attempts

From: <Valdis.Kletnieks_at_vt.edu>
Date: Fri, 07 Jul 2006 17:09:55 -0400

On Fri, 07 Jul 2006 20:29:23 +0300, ader_at_ait.edu.gr said:

> I would say that any attacker that tried to breach a system with such a
> poor security policy and failed, is under no circuimstances a threat for
> modern Network Security. I mean you left the door unlocked and a note
> saying you are not there... If the guy cant open the door he is
> incapable of harm and most probably a victim himself.

So tell me.. if you saw a flood of 62,497 totally lame ssh password probe
attempts from the same set of 4 IP addresses, what are the chances that
you'd be more likely to totally *fail* to notice a 4-packet zero-day
from one of those 4 addresses?

It's called "flying under the radar"....

  • application/pgp-signature attachment: stored
Received on Jul 07 2006
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos