Wireshark mailing list archives
Very strange SSH probe
From: "Michael Glenn" <MGlenn () cco state oh us>
Date: Mon, 12 Jul 2010 09:51:49 -0400
Anyone else seeing this? Every five to six minutes, my Linux boxes are seeing a single connection attempt via SSH. What makes this unusual is that the user ID is always 'test1' and the source IPs are all over the map; I don't think I've seen the same IP address twice yet. Interesting, yes?
___________________________________________________________________________ Sent via: Wireshark-users mailing list <wireshark-users () wireshark org> Archives: http://www.wireshark.org/lists/wireshark-users Unsubscribe: https://wireshark.org/mailman/options/wireshark-users mailto:wireshark-users-request () wireshark org?subject=unsubscribe
Current thread:
- question, how to output specific fields in a complex packet using tshark command line damker (Jul 12)
- Very strange SSH probe Michael Glenn (Jul 12)
- Re: Very strange SSH probe Martin Visser (Jul 12)
- Re: Very strange SSH probe Andrew Hood (Jul 12)
- Re: question, how to output specific fields in a complex packet using tshark command line Martin Visser (Jul 12)
- 答复: question, how to output specific fields in a complex packet using tshark command line damker (Jul 12)
- Re: [Wireshark-users] 答复: question, how to output specific fields in a complex packet using tshark command line Martin Visser (Jul 12)
- 答复: 答复: question, how to output specific fields in a complex packet using tshark command line damker (Jul 13)
- Re: [Wireshark-users] 答复: 答复: question, how to output specific fields in a complex packet using tshark command line Martin Visser (Jul 13)
- 答复: question, how to output specific fields in a complex packet using tshark command line damker (Jul 12)
- Very strange SSH probe Michael Glenn (Jul 12)