Scans for SSHd via RIPE netblocks, anyone?

From: Jay D. Dyson (jdysonat_private)
Date: Sun Oct 21 2001 - 01:06:27 PDT

  • Next message: Emre Yildirim: "suspicious http log"

    Hi folks,
    	No great shakes here, but I'm curious to know if anyone else is
    seeing concerted SSHd scans coming from RIPE netblocks lately.  I've noted
    a few here and, while I considered them oddities at first, I'm starting to
    wonder if someone (or something) across the Atlantic doesn't have the
    much-ballyhoo'd "0day for sale."
    	I'm not bored enough to see what they're really up to (yet), so I
    figured I'd just toss this out for general consideration.
    	Oh yeah, the latest scan came from
    - -Jay
      (    (                                                         _______
      ))   ))   .-"There's always time for a good cup of coffee."-.   >====<--.
    C|~~|C|~~| (>------ Jay D. Dyson - jdysonat_private ------<) |    = |-'
     `--' `--'  `- Peace without justice is life without living. -'  `------'
    Version: 2.6.2
    Comment: See for current keys.
    -----END PGP SIGNATURE-----
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see:

    This archive was generated by hypermail 2b30 : Mon Oct 22 2001 - 08:31:11 PDT