OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: OpenSSH heads-up

From: Brett Glass (brettlariat.org)
Date: Tue Sep 16 2003 - 13:41:14 CDT


At 07:43 AM 9/16/2003, Jacques A. Vidrine wrote:
  
>OK, an official OpenSSH advisory was released, see here:
><URL: http://www.mindrot.org/pipermail/openssh-unix-announce/2003-September/000063.html>

Interesting. During the past 48 hours, we've been probed several times by
hosts that connected to each of our servers on Port 22 and then disconnected
without authenticating. (They were probably just looking for the greeting.)
For example:

Sep 14 11:18:54 www sshd[16658]: fatal: Timeout before authentication for 62.107.50.87.

The source of the probes appears to be in Denmark.

Could it be that some party or parties knew about this before the announcement
and is probing for hosts to exploit?

--Brett Glass

_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"