Security Incidents mailing list archives

Re: Anyone else seeing SSH scans?


From: <sk () onlaw at>
Date: Wed, 28 Jul 2004 11:29:41 +0200


Hi!

I've also encountered these scans twice a day from different IPs.
Remarkable is that these scans alle originate from different Asian
countries 
(mostly.jp && .kr).

Is this something new, or just people looking for badly configured
machines?

I can't think of an sshd configured that badly, but who knows...

Stefan
 
-----Original Message-----
Von: Matthew Dharm [mailto:mdharm () one-eyed-alien net] 
Gesendet: Dienstag, 27. Juli 2004 19:00
An: incidents () securityfocus com
Betreff: Anyone else seeing SSH scans?

I've noticed that several *NIX machines I have running (all of which are
located in the same IP block) are periodically getting scanned via ssh
for the accounts 'test' and 'guest'.

The source IP varies with each scan.  But I'm getting about one of these
a day now.  Obviously, I don't have accounts with that name on my
systems, but still....

Is this something new, or just people looking for badly configured
machines?

Matt

-- 
Matthew Dharm                              Home:
mdharm () one-eyed-alien net 
Senior Software Designer, Momentum Computer

P:  Nine more messages in admin.policy.
M: I know, I'm typing as fast as I can!
                                        -- Pitr and Mike
User Friendly, 11/27/97


Current thread: