phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, please share.


SSH Password attacks using domain name elements as userid

Published: 2012-01-27,
Last Updated: 2012-01-27 10:08:01 UTC
by Mark Hofman (Version: 1)
Rate this diary:

1 comment(s)

A reader (Thanks Jim!) mentioned earlier today that his SSH logs were showing access attempts utilising elements of the reverse DNS name of the IP address being accessed.  For example using  isc.sans.org results in the userids isc, sans and org. This may be cause a number of hosting providers use the domain name itself as the userid for shell access for customers.  In light of the breach at dreamhost earlier this week http://blog.dreamhost.com/2012/01/21/security-update/ this may be what is going on. 

If you are noticing the same in your logs and you can share some log lines please send some in as I'd be interested in taking a peek.

Mark H

 

Keywords:
1 comment(s)

CISCO Ironport C & M Series telnet vulnerability

Published: 2012-01-27,
Last Updated: 2012-01-27 09:52:03 UTC
by Mark Hofman (Version: 1)
Rate this diary:

0 comment(s)

In case you missed it there is a vulnerability in the CISCO Ironport telnet service. Details can be found here http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120126-ironport

To mitigate the risk (if you can't upgrade just yet) is to switch off telnet on the device and use SSH to manage it instead.

Mark H

Keywords: CISCO ironport
0 comment(s)
ISC StormCast for Friday, January 27th 2012 http://isc.sans.edu/podcastdetail.html?id=2287

ISC Feature of the Week: ISC Link Back

Published: 2012-01-25,
Last Updated: 2012-01-27 03:32:10 UTC
by Adam Swanger (Version: 1)
Rate this diary:

0 comment(s)

Overview
Need to attribute information to ISC? Want to provide users with an avenue to visit the ISC site? Want to link directly to the ISC Stormcast, Infocon or other information? These methods and more are listed on out ISC Linkback Page! https://isc.sans.edu/linkback.html

Features

Note
This works as DShield also. Just view the dshield.org url http://dshield.org/linkback.html


Don't see a link you'd like to use? Suggest in the comments section below or send any questions or comments in the contact form https://isc.sans.edu/contact.html

--
Adam Swanger, Web Developer (GWEB)
Internet Storm Center (http://isc.sans.edu)

Keywords: ISC feature
0 comment(s)

If you have more information or corrections regarding our diary, please share.

Diary Archive

DateAuthorTitle
2012-01-27 Mark Hofman CISCO Ironport C & M Series telnet vulnerability
2012-01-27 Mark Hofman SSH Password attacks using domain name elements as userid
2012-01-25 Adam Swanger ISC Feature of the Week: ISC Link Back
2012-01-25 Bojan Zdrnja pcAnywhere users – patch now!
2012-01-24 Bojan Zdrnja Is it time to get rid of NetBIOS?
2012-01-22 Johannes Ullrich Javascript DDoS Tool Analysis
2012-01-22 Lorna Hutcheson Mailbag - "Attacks"
2012-01-21 Mark Hofman The privacy hodgepodge and IP Addresses
2012-01-21 Guy Bruneau DNS Sinkhole Scripts Fixes/Update
2012-01-19 Chris Mohan WHOIS contacts are your friends
Folder Icon Complete Archive
Search Diaries:

Diary Tagslink arrow

  ironport     workaround     firefox     webattacks     cisco     isc     flash     ssh     ssl     pcanywhere     printer     windows 7     dns     acrobat     win32ksys     windows     gtdl     nmap     aspnet     holiday greetings     holiday tips     badware     exploit     adobe black tuesday     coldfusion     advertising     password security     opendlp     scripting stderr     bind     wifi     microsoft security bulletin advance notification     mailbag     flex     netbios     black tuesday     nbns spoofing     scam     vulnerability     oracle patches     webserver     0day     stratfor     vulnerabilities     blackhole     html5     patch tuesday     dos     microsoft msft patch tuesday patches prerelease     symantec     wps     ddos     microsoft     patch     type a     oracle     dnssec     breach     exploit kit     malware     whois info     java     quarterly     anonymous     data breach     0 day     brute force     zappos     dns sinkhole     adobe     sql injection attack     microsoft patch tuesday     rootkit     isc feature     obfuscation     spidermonkey     tcpflow     stratford     chrome     javascript