Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 9 Feb 2017 18:22:23 -0500
From:      Jon Radel <jon@radel.com>
To:        sixto areizaga <thenewcq@optimum.net>, freebsd-questions@freebsd.org
Subject:   Re: wireshark issue
Message-ID:  <c2dd4d2c-0e7c-42f0-9eef-2cb734421767@radel.com>
In-Reply-To: <20170209174405.5d551b88@newer.home>
References:  <CAKM9q91KKxtqXRTG84Szefww%2BR--S1A7wvgSx5LV3jNS90=4qw@mail.gmail.com> <20170209174405.5d551b88@newer.home>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
On 2/9/17 5:44 PM, sixto areizaga wrote:
> Has anyone experienced something similar or have any info about the
> following using wireshark...
> 
>  
> I was working on a webpage [that isn't up yet] no outside connections
> established, I started apache [from computer #1], started wireshark
> [same node] and opened firefox [computer #2] and for the url I did a
> 192.168.etc.etc
> 
> looking though packets transfered there was a transfer from outside my
> network - (the ip might be in China) - it used putty [with sshv2] to
> get a server/client key exchange.
> 
> it looked like a mobile device running a script except using putty 
> 
> anyone have a similar problem? 

Somebody already answered the first time you asked this question.  Why
ask again?

Yes, there are people out on the Internet who constantly scan ipv4
addresses for any number of interesting servers, and that most certainly
includes ssh servers.  This should be obvious if you have a machine that
allows for connections to port tcp/22 from the Internet at large--just
look at the log of failed connection attempts or fire up a copy of
wireshark.

If you don't like it, block the traffic using a firewall.  You can also
move your ssh server to a different port, which will reduce the noise
considerably and pretty predictably start an argument about "security by
obscurity is not really security."

Really, the only part of your question that *I* find remotely
interesting is how you determined that the client is actually a copy of
putty running on a mobile device, or at least looks like it is?


-- 
--Jon Radel
jon@radel.com


[-- Attachment #2 --]
0	*H
010
	`He0	*H

00#SanzTgk!0
	*H
0o10	USE10U
AddTrust AB1&0$UAddTrust External TTP Network1"0 UAddTrust External CA Root0
141222000000Z
200530104838Z010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0"0
	*H
0

zSNpRV&IQZI`zQBy"aNv#
J	n=ٺ.CRC|2PȦOZϓ%{0dV*$3DiFK3@@:*S= a<UNv%!)|qvO_T{5R"=,0-1YR73i-C֥wgQ'뼥8v8ߌIs:2:=F:WtaP@?⟢!00U#0z4&&T$T0UakᢠOg£0U0U00U%0++0U 
00U 0DU=0;09753http://crl.usertrust.com/AddTrustExternalCARoot.crl05+)0'0%+0http://ocsp.usertrust.com0
	*H
*nU:Uka+	#fjow^a}[jr
AX&MX"cR6}Xޫ;cs{B#ʶM>K-ػBKiۦ74{:ǟO4ne6d)5ֱqC>2Svʆ4,Jؙ
␒ZBj#!eջ~ꌅ b:,Yř38zyJ&|00sT<}k
`i
0
	*H
010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CA0
150330000000Z
180329235959Z010	UUS10U2215010	UVA10USpringfield10U	6917 Ridgeway Dr.10U
Jon T. Radel1200U)Issued through Jon T. Radel E-PKI Manager10UCorporate Secure Email10U	Jon Radel10	*H
	
jon@radel.com0"0
	*H
0
aЩ@@g3eGރ͛;	d#>q7&Hf
:3vL"jV#Xݷ>U-H[$SUڻ{Ϝ,z¶IchO=rcyrnv.Vh7k;%ueYuӬ󯅅nz6!| !Aȡ+,u+ 
CAպF-un#vjUJWnk%j]
2JPkl00U#0akᢠOg£0UE|GDp/ʚB0U0U00U%0++0FU ?0=0;+10+0)+https://secure.comodo.net/CPS0]UV0T0RPNLhttp://crl.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crl0+00X+0Lhttp://crt.comodoca.com/COMODOSHA256ClientAuthenticationandSecureEmailCA.crt0$+0http://ocsp.comodoca.com0U0
jon@radel.com0
	*H
KS`?H_D`8G߿VbĘ<tB-Ӈї|{'Ũݹg0Gp$%F(;*MO*gt$@t6,?0|#ăz,&!{j2i[%b7ߪP+9G㲍["y<?8rZ'[UR6%L̤
w"=:L~Ƨ^jf36 OP1•.}(e1A0=0010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0
	`Hea0	*H
	1	*H
0	*H
	1
170209232223Z0/	*H
	1" B1cB#y(!KQҗ0l	*H
	1_0]0	`He*0	`He0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0*H
	1010	UGB10UGreater Manchester10USalford10U
COMODO CA Limited1A0?U8COMODO SHA-256 Client Authentication and Secure Email CAsT<}k
`i
0
	*H
FfەsӧS+7
0MC	[@hFVWIƲutßezsnUH*CS&JPuD}*E.C5$0疢V8}9yFق7)ļ{@d,CPk_zż>㊟b{bBRsK+nG%$dXyrsxj+04X@d<RHM³™zxEQITw{

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?c2dd4d2c-0e7c-42f0-9eef-2cb734421767>