cvsup

Vladimir Kotal vladimir.kotal at jet2web.cz
Sat Jan 5 19:41:37 CET 2002



Pro masivni scany verzi ssh zajiste uvitaji vetsi organizace 
security/scanssh z ports (plati pro Open/Free/NetBSD).
Vice napr. viz http://openssh.com/usage/index.html


v.


On Fri, Jan 04, 2002 at 07:37:00PM +0100, Robert Schlesinger wrote:
> Nevim, jeslti to s tim souvisi, ale tady predavam jeden zajimavy mail:
> >>>>>>>>>>>>>>>>>>>>>>>>>>>>>
> Tohle prislo v konferenci spravcu siti AVCR:
> 
> Mili kolegove,
> 
> v logu nasich firewallu vidime v poslednich dnech hodne utoku
> na portu 22 (SSH). Neco o tom pisou i CERTi, konkretne
> http://www.cert.org/advisories/CA-2001-35.html . Bohuzel neprilis
> konkretne.
> 
> Do FZU to prislo v nasledujici podobe. Soustavny sken na portu 22
> postupne na jednotlive adresy, na kazdou dvakrat. Z nich si to vybralo
> jeden na kterem byl OpenSSH-1.2.2, na nej stovky pokusu az se to
> nejak prorazilo. Jine verze SSH to jenom osahlo a nechalo v klidu:
> SSH-1.5-1.2.26 SSH-1.5-1.2.27 OpenSSH_2.3.0p1 OpenSSH_2.9.9p2 .
> Tim nerikam ze ty jine verze jsou bez diry. Proste takhle to u nas
> probehlo. Kraknuty pocitac - byl to linux - byl potom vyuzit k dalsim
> utokum mimo nasi sit.
> 
> Rychly test jaka verze SSH je na danem stroji:
> 
> telnet ten-stroj 22
> 
> To je vsecko, treba to nekoho bude zajimat.
> >>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>
> 
> 
> ----- Original Message -----
> From: "Peter Vongrej" <monkus at eskulap.health.gov.sk>
> To: <users-l at freebsd.cz>
> Sent: Friday, January 04, 2002 9:47 AM
> Subject: cvsup
> 
> 
> > root@[luster /root/cron] # sh cvs-ports
> > Parsing supfile "/root/cron/ports"
> > Connecting to cvsup.de.freebsd.org
> > Connected to cvsup.de.freebsd.org
> > Server software version: SNAP_16_1e
> > Negotiating file attribute support
> > Exchanging collection information
> > Establishing multiplexed-mode data connection
> > ChannelMux.Accept failed: Connection closed
> >
> > zrazu mi to zacalo robit na vsetkych bsd serveroch
> > je to global ci len moj lokalny problem ?
> > vcera som nahodil cvsup-16.1f a odvtedy mam zdani, ze je niektory
> ChannelMux.*3 vadny
> > any idea ?
> >
> > monkus
> >
> >



More information about the Users-l mailing list