Re: OpenSSH 3.4p1 Trouble on SCO 5.0.5?



Steve M. Fabac, Jr. wrote:
Bill Vermillion wrote:
In article <47E6160C.7080405@xxxxxxx>,
Steve M. Fabac, Jr. <smfabac@xxxxxxx> wrote:
I have a client running SCO 5.0.5 with OpenSSH 3.4p1
installed.
Since SSH was installed, we have been getting hits from
people on the Internet scanning port 22.
Normally they give up and go away. However, I have noticed
an unusual number of scans from foreign IP addresses using
valid names on the system (the names below in the block for
a single source IP are the *only* names logged from that
IP):
....

Anybody have any ideas, thoughts or comments on this?

Steve,

what about using tcp_wrappers as to perform a "route delete" on the offending IP?

If memory serves, there was a porting of tcp_wrapper for SCO OS5 on a TLS076a
on the FTP site:

ftp://ftp.sco.com/pub/TLS/tls076a.tcp_wrappers.tar.Z

Hope this helps!

Ciao,
Rob
.



Relevant Pages

  • Slightly OT: port-knocking etc. (was Re: ipkungfu logging not working )
    ... Is ipkungfu rejected packets ending up in your /var/log/syslog file? ... I don't get a lot of hits on the iptables because the machine is behind a ... hopeful scanners (they have to be *very* hopeful since my sshd_config ... I use port-knocking to access ssh from ...
    (Ubuntu)
  • Re: Odd ssh attacks?
    ... On Friday 20 July 2007 10:30:15 David Ford wrote: ... More than N hits per 60 seconds for ssh and you get firewalled for an ... Por que não é bom escrever o reply em cima do email? ...
    (Ubuntu)
  • Increase in SSH scans
    ... I will normally get two or three hits on ssh per day. ... From LogWatch this morning: ... At least one of the hosts involved shows up at dshield.org with evidence ...
    (Incidents)
  • Re: TCPIP SSH failure logging
    ... >I'm getting an increasing number of hits on SSH, attempting to crack ... Other than the immediate intrusions records, ...
    (comp.os.vms)