Jul 24 2004

SSH Brute Force Password attmepts

Published by Martin at 9:30 am under Hacking

The Internet Storm Center is warning of brute force password hack attempts against SSH. I’m waiting to see more specific information, but I have been seeing attempts against my own SSH daemon, specifically trying to use the ‘guest’ and ‘test’ accounts. Since neither of those accounts exist on my systems, I feel pretty safe, but I do find it interesting that this has been happening. I hope to find out more soon.

I finally got around to reading the rest of the diary for the 23rd. I’m impressed with the ‘Follow the Bouncing Malware” article. The author built a sacrificial web surfing box and monitored all of the malware that was downloaded while going to several popular sites. I’ve thought about doing the same in the past, but the time involved is more than I have to spare. I’d be interested in seeing the difference between doing this with Internet Explorer and Firefox. Since I switched to Firefox, I haven’t had to run AdAware nearly as often. But as Firefox becomes a better alternative to IE, I expect the scumware authors will start targetting it a lot more.

[Slashdot] [Digg] [Reddit] [del.icio.us] [Facebook] [Technorati] [Google] [StumbleUpon]

One Response to “SSH Brute Force Password attmepts”

  1. lucason 30 Jul 2004 at 8:20 am

    Yes I am detecting the same attempts on my sshd through snort?? Strange..