I'm not exactly a newbie to Linux but I could still
use some suggestions. I was reviewing my system logs
and found where someone was trying to break in to my
machine via ssh. Again.

I always find these attempts amusing since the
attempts are never succcessful. Even so, I always
report them to the responsible ISPs.

But I have seen something I don't quite understand.
While they almost always start out with a simple
dictionary attack, they quite often revert to
something different - their attempts get logged as
attempts to connect to my port 22 from varying high
port numbers on thier machines. What's the idea behind
this?  The log file I'm looking at now shows the user
trying to connect from port 35093, then from port
35087, then from 35086, then from port 35088. Why are
they varying the port number on their side?

This isn't a high priority thing, I'm just curious as
to what these idiots think they can accomplish by this
technique.

Dan


                
____________________________________________________
Start your day with Yahoo! - make it your home page 
http://www.yahoo.com/r/hs 
 


------------------------ Yahoo! Groups Sponsor --------------------~--> 
<font face=arial size=-1><a 
href="http://us.ard.yahoo.com/SIG=12hb3u9bj/M=362329.6886308.7839368.1510227/D=groups/S=1705006580:TM/Y=YAHOO/EXP=1124757111/A=2894321/R=0/SIG=11dvsfulr/*http://youthnoise.com/page.php?page_id=1992
">Fair play? Video games influencing politics. Click and talk back!</a>.</font>
--------------------------------------------------------------------~-> 

To unsubscribe from this list, please email [EMAIL PROTECTED] & you will be 
removed. 
Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/LINUX_Newbies/

<*> To unsubscribe from this group, send an email to:
    [EMAIL PROTECTED]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
 


Reply via email to