Re: Some new SSH exploit script?

From: R. DuFresne (dufresne@sysinfo.com)
Date: Fri Jun 09 2006 - 13:50:46 EDT


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Fri, 9 Jun 2006, Paul Robertson wrote:

> On 6/8/06, R. DuFresne <dufresne@sysinfo.com> wrote:
>
>> Log cruft is a pretty lame reason and rational for making a choice to
>> implement a non-standard port setting, admins should have the skills to
>> filter and parse logs in a manner such that the cruft does not interfere
>> with their daily log monitoring chores, else they have likely a lot of
>> other cruft that must as well be driving them to near madness as well not
>> relating to sshd and the kiddie brute-forcing tool of the week.
>
> It's all about capacity planning- if you didn't plan enough log
> capacity, didn't plan enough CPU for real-time analysis, or don't
> trust real-time filtering, then moving the port might just be the
> right thing to do.

This is a different argument though, and correctable in future capacity
planning and system refreshes.

Thanks,

Ron DuFresne
- --
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         admin & senior security consultant: sysinfo.com
                         http://sysinfo.com
Key fingerprint = 9401 4B13 B918 164C 647A E838 B2DF AFCC 94B0 6629

...We waste time looking for the perfect lover
instead of creating the perfect love.

                 -Tom Robbins <Still Life With Woodpecker>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.2 (GNU/Linux)

iD8DBQFEibT5st+vzJSwZikRAu7lAKCsZ++zCc6biK3kLG8JiPVzvc0ZnQCePjL6
wuPHbLQeBpfBJYrlZDVrlNE=
=1gIT
-----END PGP SIGNATURE-----

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security?
Why not go with the #1 solution - Cenzic, the only one to win the Analyst's
Choice Award from eWeek. As attacks through web applications continue to rise,
you need to proactively protect your applications from hackers. Cenzic has the
most comprehensive solutions to meet your application security penetration
testing and vulnerability management needs. You have an option to go with a
managed service (Cenzic ClickToSecure) or an enterprise software
(Cenzic Hailstorm). Download FREE whitepaper on how a managed service can
help you: http://www.cenzic.com/news_events/wpappsec.php
And, now for a limited time we can do a FREE audit for you to confirm your
results from other product. Contact us at request@cenzic.com for details.
------------------------------------------------------------------------------



This archive was generated by hypermail 2.1.7 : Sat Apr 12 2008 - 10:56:04 EDT