[nsp-sec] ACK AS209 / SSH scanning - we are now up over 1000
Smith, Donald
Donald.Smith at qwest.com
Tue Aug 10 12:53:27 EDT 2010
We had a reader write in about this this morning. He pointed to this short write up.
http://www.directadmin.com/forum/showthread.php?p=185128
(coffee != sleep) & (!coffee == sleep)
Donald.Smith at qwest.com gcia
> -----Original Message-----
> From: nsp-security-bounces at puck.nether.net
> [mailto:nsp-security-bounces at puck.nether.net] On Behalf Of
> Scott A. McIntyre
> Sent: Tuesday, August 10, 2010 10:34 AM
> To: nsp-security at puck.nether.net
> Subject: Re: [nsp-sec] ACK AS209 / SSH scanning - we are now
> up over 1000
>
> ----------- nsp-security Confidential --------
>
>
>
> On 10/08/10 18:02 , Smith, Donald wrote:
> > ----------- nsp-security Confidential --------
> >
> > Netflow shows that our ips identified by Joel are in fact
> scanning for tcp 22 and based on the small size of the
> packets with the ack bit set they are attempting to
> bruteforce others ssh accounts too:(
> >
> >
>
> We've had several customers confirm phpMyAdmin on the systems pwned -
> anyone have details as to which of the known exploits this
> is, or, is it
> something "new"?
>
> Cheers,
>
> Scott A. McIntyre
> XS4ALL Internet B.V.
>
>
>
> _______________________________________________
> nsp-security mailing list
> nsp-security at puck.nether.net
> https://puck.nether.net/mailman/listinfo/nsp-security
>
> Please do not Forward, CC, or BCC this E-mail outside of the
> nsp-security
> community. Confidentiality is essential for effective
> Internet security counter-measures.
> _______________________________________________
>
This communication is the property of Qwest and may contain confidential or
privileged information. Unauthorized use of this communication is strictly
prohibited and may be unlawful. If you have received this communication
in error, please immediately notify the sender by reply e-mail and destroy
all copies of the communication and any attachments.
More information about the nsp-security
mailing list