Re: OpenSSH 3.4p1 Trouble on SCO 5.0.5?



Steve M. Fabac, Jr. wrote:
I have a client running SCO 5.0.5 with OpenSSH 3.4p1
installed.

Since SSH was installed, we have been getting hits from
people on the Internet scanning port 22.

Normally they give up and go away. However, I have noticed
an unusual number of scans from foreign IP addresses using
valid names on the system (the names below in the block for
a single source IP are the *only* names logged from that
IP):

Are you running an SMTP server that can be probed for valid addresses? A lot of those are common system names, as well. Someone could have gotten a valid /etc/passwd list by any of a number of other means, published it, and be probing them with their rootkit tools.

However, 5.0.5 is way out of date. It has no, and I mean *NO* business having any direct exposure to the Internet. If you have to run services like SSH to it, it should be through an external firewall with some sort of logging, and preferably not run popular services like SSH on port 22.



Anybody have any ideas, thoughts or comments on this?

It looks like normal port scanning by crackers. Any machine exposed to the Internet will see this sort of scanning, with the caveat that the user names may be obtained from some other source (such as public email addresses off of the web) or may be from random guessing of likely first-name addresses.
.



Relevant Pages

  • Re: SSH safety
    ... SSH safety (J.L. ... FC3 missing KDE menu items ... I was wondering how safe it is to open the ssh port up to the internet. ...
    (Fedora)
  • Re: iptables forwarding question
    ... > firewall for my cable internet. ... > currently have a small iptables setup going to forward all the machine ... You want to be able to use regular SSH to connect to any one of these ... SSH uses port 22 - of which you have only one. ...
    (comp.os.linux.networking)
  • Re: Tunnneling?
    ... >> might be able to do something temporarily using ssh and port forwarding. ... > I don't have a machine with a real IP on the internet on my network. ... > That could theoretically be set-up for a tunnel or something like that... ...
    (comp.os.linux.networking)
  • Re: SSH safety
    ... Is it safe to open ssh up to the internet, ... Every open port creates some risk. ...
    (Fedora)
  • Re: Deutsche-Telekom sets the standard for network security! (??)
    ... I would have to agree that one should be selective when reporting a port ... I would bet money that 95% of the people scanning ports are not ... I only report it if I see the same IP or domain ... > and internet was created in the atmosphere that every computer should be ...
    (comp.os.linux.security)