Change in recent ssh scanning

This is a discussion on Change in recent ssh scanning within the Linux Security forums, part of the System Security and Security Related category; I've just reviewed some of my recent packet logs, and I notice a change in the recent wave of ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-16-2004
Allen Kistler
 
Posts: n/a
Default Change in recent ssh scanning

I've just reviewed some of my recent packet logs, and I notice a change
in the recent wave of ssh scanning.
(See http://isc.sans.org/diary.php?date=2004-07-28 for background.)

Usually the scanner just tries to connect as a lame generic user and
guess the password. Starting about a week or so ago, the packets go
like so....

Them:port > Me:ssh - syn (sequence #)
Me:ssh > Them:port - syn,ack
Them:port > Me:ssh - syn (sequence # + 300)
Me:ssh > Them:port - syn,ack
Them:port > Me:ssh - ack
....
and the rest as usual.

"Them" is sending a second syn from the same source port, but with an
initial sequence number incremented by 300, and starting the handshake
over again.

Question: Is there any reason to behave this way? That is, is there
some reason (like some vulnerability) to just restart the handshake on
the identical connection?

(Side issue: It's been a while since I've read RFCs, but I was a little
surprised that my server didn't even blink at the oddity. I would
expect a rst or something. What's _supposed_ to happen?)

I suspect the answer is that the scripter has just introduced a bug into
his scanner as he plays with the code to add features. Nevertheless,
does anyone know definitively?
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




All times are GMT +1. The time now is 01:23 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0