From owner-freebsd-security@FreeBSD.ORG Tue Dec 8 11:21:34 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id F049B106568B for ; Tue, 8 Dec 2009 11:21:34 +0000 (UTC) (envelope-from freebsd-security@m.gmane.org) Received: from lo.gmane.org (lo.gmane.org [80.91.229.12]) by mx1.freebsd.org (Postfix) with ESMTP id A52188FC12 for ; Tue, 8 Dec 2009 11:21:34 +0000 (UTC) Received: from list by lo.gmane.org with local (Exim 4.50) id 1NHxds-0007S8-Ae for freebsd-security@freebsd.org; Tue, 08 Dec 2009 11:50:04 +0100 Received: from 200.41.broadband11.iol.cz ([90.178.41.200]) by main.gmane.org with esmtp (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Tue, 08 Dec 2009 11:50:04 +0100 Received: from gamato by 200.41.broadband11.iol.cz with local (Gmexim 0.1 (Debian)) id 1AlnuQ-0007hv-00 for ; Tue, 08 Dec 2009 11:50:04 +0100 X-Injected-Via-Gmane: http://gmane.org/ To: freebsd-security@freebsd.org From: martinko Date: Tue, 08 Dec 2009 01:09:03 +0100 Lines: 15 Message-ID: References: <200912010120.nB11Kjm9087476@freefall.freebsd.org> <200912010522.WAA03022@lariat.net> <200912011724.KAA10851@lariat.net> <200912011909.nB1J9JRM070879@lava.sentex.ca> <200912020145.SAA17523@lariat.net> <200912020150.nB21ossm072930@lava.sentex.ca> <4B1662BB.8000908@gmail.com> <200912021324.nB2DOc58001138@lava.sentex.ca> <20091202090707.f563976d.wmoran@collaborativefusion.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Complaints-To: usenet@ger.gmane.org X-Gmane-NNTP-Posting-Host: 200.41.broadband11.iol.cz User-Agent: Mozilla/5.0 (X11; U; FreeBSD i386; en-US; rv:1.8.1.18) Gecko/20081125 SeaMonkey/1.1.13 In-Reply-To: <20091202090707.f563976d.wmoran@collaborativefusion.com> Sender: news Subject: Re: Increase in SSH attacks as of announcement of rtld bug X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 08 Dec 2009 11:21:35 -0000 Bill Moran wrote: > In response to Mike Tancsa : >> Yes, thats the latest pattern I have been seeing-- distributed, slow >> and coordinated. Here is a sample from one of my honeypots. The >> only way to deal with them I found is to have multiple sensors >> throughout my network and aggregate the data. Otherwise, each IP >> only appears every few hrs in the logs. > > I deal with it by immediately blocking any host that generates an > "invalid user" error. > > Of course, that won't work for everyone :( > and if it's just a typo on user part ?