OpenSSH heads-up

Brett Glass brett at lariat.org
Tue Sep 16 11:41:56 PDT 2003


At 07:43 AM 9/16/2003, Jacques A. Vidrine wrote:
  
>OK, an official OpenSSH advisory was released, see here:
><URL: http://www.mindrot.org/pipermail/openssh-unix-announce/2003-September/000063.html>

Interesting. During the past 48 hours, we've been probed several times by
hosts that connected to each of our servers on Port 22 and then disconnected
without authenticating. (They were probably just looking for the greeting.)
For example:

Sep 14 11:18:54 www sshd[16658]: fatal: Timeout before authentication for 62.107.50.87.

The source of the probes appears to be in Denmark.

Could it be that some party or parties knew about this before the announcement
and is probing for hosts to exploit?

--Brett Glass





More information about the freebsd-security mailing list