phpbb and sql errors asp sqlserver odbc sql errors

Today´s Diary

If you have more information or corrections regarding our diary, please share.


SSH Password attacks using domain name elements as userid

Published: 2012-01-27,
Last Updated: 2012-01-27 10:08:01 UTC
by Mark Hofman (Version: 1)
Rate this diary:

1 comment(s)

A reader (Thanks Jim!) mentioned earlier today that his SSH logs were showing access attempts utilising elements of the reverse DNS name of the IP address being accessed.  For example using  isc.sans.org results in the userids isc, sans and org. This may be cause a number of hosting providers use the domain name itself as the userid for shell access for customers.  In light of the breach at dreamhost earlier this week http://blog.dreamhost.com/2012/01/21/security-update/ this may be what is going on. 

If you are noticing the same in your logs and you can share some log lines please send some in as I'd be interested in taking a peek.

Mark H

 

Keywords:
1 comment(s)

CISCO Ironport C & M Series telnet vulnerability

Published: 2012-01-27,
Last Updated: 2012-01-27 09:52:03 UTC
by Mark Hofman (Version: 1)
Rate this diary:

0 comment(s)

In case you missed it there is a vulnerability in the CISCO Ironport telnet service. Details can be found here http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20120126-ironport

To mitigate the risk (if you can't upgrade just yet) is to switch off telnet on the device and use SSH to manage it instead.

Mark H

Keywords: CISCO ironport
0 comment(s)
ISC StormCast for Friday, January 27th 2012 http://isc.sans.edu/podcastdetail.html?id=2287

ISC Feature of the Week: ISC Link Back

Published: 2012-01-25,
Last Updated: 2012-01-27 03:32:10 UTC
by Adam Swanger (Version: 1)
Rate this diary:

0 comment(s)

Overview
Need to attribute information to ISC? Want to provide users with an avenue to visit the ISC site? Want to link directly to the ISC Stormcast, Infocon or other information? These methods and more are listed on out ISC Linkback Page! https://isc.sans.edu/linkback.html

Features

Note
This works as DShield also. Just view the dshield.org url http://dshield.org/linkback.html


Don't see a link you'd like to use? Suggest in the comments section below or send any questions or comments in the contact form https://isc.sans.edu/contact.html

--
Adam Swanger, Web Developer (GWEB)
Internet Storm Center (http://isc.sans.edu)

Keywords: ISC feature
0 comment(s)

If you have more information or corrections regarding our diary, please share.

Diary Archive

DateAuthorTitle
2012-01-27 Mark Hofman CISCO Ironport C & M Series telnet vulnerability
2012-01-27 Mark Hofman SSH Password attacks using domain name elements as userid
2012-01-25 Adam Swanger ISC Feature of the Week: ISC Link Back
2012-01-25 Bojan Zdrnja pcAnywhere users – patch now!
2012-01-24 Bojan Zdrnja Is it time to get rid of NetBIOS?
2012-01-22 Johannes Ullrich Javascript DDoS Tool Analysis
2012-01-22 Lorna Hutcheson Mailbag - "Attacks"
2012-01-21 Mark Hofman The privacy hodgepodge and IP Addresses
2012-01-21 Guy Bruneau DNS Sinkhole Scripts Fixes/Update
2012-01-19 Chris Mohan WHOIS contacts are your friends
Folder Icon Complete Archive
Search Diaries:

Diary Tagslink arrow

  holiday tips     opendlp     printer     html5     aspnet     nmap     data breach     microsoft patch tuesday     vulnerabilities     oracle patches     sql injection attack     webserver     dns     isc     adobe black tuesday     ssl     chrome     nbns spoofing     win32ksys     java     anonymous     black tuesday     exploit     oracle     patch tuesday     badware     malware     0day     firefox     javascript     rootkit     breach     dos     stratfor     flash     microsoft security bulletin advance notification     stratford     bind     advertising     ddos     symantec     microsoft msft patch tuesday patches prerelease     webattacks     password security     type a     hp     cisco     whois info     coldfusion     gtdl     pcanywhere     obfuscation     zappos     acrobat     scripting stderr     spidermonkey     exploit kit     dnssec     0 day     holiday greetings     vulnerability     adobe     microsoft     netbios     dns sinkhole     workaround     printers     wps     ssh     blackhole     tcpflow     wifi     patch     windows     isc feature     mailbag     flex     scam     windows 7     ironport     brute force     quarterly