From owner-freebsd-security@FreeBSD.ORG Sun Oct 2 23:29:23 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 69F6216A41F for ; Sun, 2 Oct 2005 23:29:23 +0000 (GMT) (envelope-from brett@lariat.org) Received: from lariat.net (lariat.net [65.122.236.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id DBECF43D49 for ; Sun, 2 Oct 2005 23:29:22 +0000 (GMT) (envelope-from brett@lariat.org) Received: from anne-o1dpaayth1.lariat.org (IDENT:ppp1000.lariat.net@lariat.net [65.122.236.2]) by lariat.net (8.9.3/8.9.3) with ESMTP id RAA29555; Sun, 2 Oct 2005 17:29:17 -0600 (MDT) X-message-flag: Warning! Use of Microsoft Outlook renders your system susceptible to Internet worms. Message-Id: <6.2.3.4.2.20051002171946.08f98c08@localhost> X-Mailer: QUALCOMM Windows Eudora Version 6.2.3.4 Date: Sun, 02 Oct 2005 17:29:12 -0600 To: Kevin Day From: Brett Glass In-Reply-To: <9153DDB6-6FD4-4B14-9997-D6145F80AC3A@dragondata.com> References: <6.2.3.4.2.20051002153930.07a50528@localhost> <9153DDB6-6FD4-4B14-9997-D6145F80AC3A@dragondata.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Cc: freebsd-security@freebsd.org Subject: Re: Repeated attacks via SSH X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 02 Oct 2005 23:29:23 -0000 At 05:05 PM 10/2/2005, Kevin Day wrote: >This is pretty common, I'm afraid. SSH scanning with brute force >password guessing has gone through the roof in the last 9-12 months, >but it's been going on for years. > >We announce a /19 worth of space, and see several hundred ssh >connects per second across it. The amount of junk port 22 traffic has >exceeded the amount of junk port 25 traffic for us now. For us, it just did this weekend. Major swarm of bots, mostly from the UK and eastern Europe. I can't imagine we're alone. The sudden increase -- and the tactic of harvesting e-mail addresses and trying to match them to accounts -- were the reasons I decided to post. People are going to want to make their security a bit tighter. Spam, worms, bots.... This Internet thang is sure becoming a cesspool. --Brett