[ale] SSH attempts

Michael H. Warfield mhw at WittsEnd.com
Mon Sep 12 11:27:17 EDT 2011

On Mon, 2011-09-12 at 11:05 -0400, David Hillman wrote: 
> According to the PortSentry logs for my server, I have received thousands of
> connection attempts via SSH port 22.  Of course, that is not the port the
> real SSH service is listening on. Logins were also disabled for root.
> What's interesting is the IP addresses all belong to Serverloft (
> www.serverloft.eu); most attempts came from (
> loft4385.serverloft.eu).  I am guessing someone with a few VPS boxes has
> nothing better to do than use up network bandwidth to terrorize the rest of
> us.  Or, maybe those boxes have been compromised.

> I have e-mailed the folks over over at Serverloft, but I don't expect
> anything of it.  Is there anything else I can do?

It's just noise.  They're not getting in so you can ignore them.
Happens all the time around here.  If you want some amusement, set up an
ssh honeypot and catch all their password attempts.  You'll be left
shaking your head in total disbelief.  "Do they really think THOSE
things will actually work?!?!?"  Yeah, not only do they believe they
work, there actually are people stupid enough to use stupid passwords
who actually have ssh shell access that it makes it worth it for them to
do this.  Sigh...  Some of the passwords might surprise you but they're
all still LAME.

Michael H. Warfield (AI4NB) | (770) 985-6132 |  mhw at WittsEnd.com
   /\/\|=mhw=|\/\/          | (678) 463-0932 |  http://www.wittsend.com/mhw/
   NIC whois: MHW9          | An optimist believes we live in the best of all
 PGP Key: 0x674627FF        | possible worlds.  A pessimist is sure of it!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 482 bytes
Desc: This is a digitally signed message part
Url : http://mail.ale.org/pipermail/ale/attachments/20110912/238fed83/attachment.bin 

More information about the Ale mailing list