Toot

Written by scy on 2024-10-29 at 21:46

Interesting type of attack: People sending out TCP packets with a spoofed source address, targeting port 22 on random (or not) IP addresses on the net.

Not to probe whether there's SSH on that server, but to generate abuse reports against the spoofed IP, in order to force it off the net.

https://delroth.net/posts/spoofed-mass-scan-abuse/

Keep this in mind when you receive abuse reports. Especially if you're an ISP.

[#]infosec #networking #sysadmin

=> More informations about this toot | View the thread | More toots from scy@chaos.social

Mentions

Tags

=> View infosec tag | View networking tag | View sysadmin tag

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113392901473623293
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
228.926462 milliseconds
Gemini-to-HTML Time
0.440299 milliseconds

This content has been proxied by September (3851b).