method
September 14th, 2005, 08:30 AM
It's probably a n00b question and I don't even realise it... but I'm still gonna ask...
I run a bunch of servers, all of them linux (and i'm pretty rusty with linux.. so that's a good start!!!).
...and I've noticed looking through logs that there have been a lot.. and I mean a LOT of attempts to SSH in with invalid credentials. Dictionary attacks, bruteforce, you name it. But... nobody bothers with telnet, even though it's open.
Anyone know why the hackers/botnets/dickheads/etc. are aiming for SSH and ignoring telnet?
Is it indicative of me having a vulnerable SSH service? (I remember before closing it, seeing something about OpenSSH being a vulnerability)... any ideas?
I run a bunch of servers, all of them linux (and i'm pretty rusty with linux.. so that's a good start!!!).
...and I've noticed looking through logs that there have been a lot.. and I mean a LOT of attempts to SSH in with invalid credentials. Dictionary attacks, bruteforce, you name it. But... nobody bothers with telnet, even though it's open.
Anyone know why the hackers/botnets/dickheads/etc. are aiming for SSH and ignoring telnet?
Is it indicative of me having a vulnerable SSH service? (I remember before closing it, seeing something about OpenSSH being a vulnerability)... any ideas?