dos

  1. B

    Solved I see many ESTABLISHED connections from one IP to my ssh (port 22) without authentication. Is this a new attack on ssh that I am not aware off?

    I noticed that on my public ssh server at port 22, I see a large number of ssh ESTABLISHED connections, that do not authenticate and stay in the ETABLISHED state sending keep alives. Specifically, in the nestat I see many entries of the form: tcp4 12 0 myIP:.22 156.0.96.22.52574...
Back
Top