|
Security Incidents
mailing list archives
remote openssh probe or crack?.
From: "Lic. Rodolfo Gonzalez Gonzalez" <rgg () cs buap mx>
Date: Wed, 12 Jun 2002 18:13:08 -0500 (CDT)
Hello,
I got these lines in "messages" in a RedHat 6.2 box:
Jun 10 09:51:57 server sshd[9100]: Did not receive identification string
from 64.90.65.19
Jun 10 09:52:06 server sshd[9117]: Did not receive identification string
from 64.90.65.19
Jun 11 03:07:56 server sshd[8684]: Did not receive identification string
from 216.127.64.48
Jun 11 03:07:56 server sshd[8688]: Did not receive
identification string from 216.127.64.48
Jun 12 08:14:03 server sshd[22853]: Did not receive identification string
from 61.84.218.135
Jun 12 08:14:05 server sshd[22871]: Did not receive
identification string from 61.84.218.135
I guess they're related to the latest openssh vulnerability, but I don't
know if this could be caused by a succesful remote exploitation or if this
is just a probe/scan. Any comments on this are appreciated.
Thank you.
Rodolfo.
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
By Date
By Thread
Current thread:
- remote openssh probe or crack?. Lic. Rodolfo Gonzalez Gonzalez (Jun 12)
|