[plug] Recent increase in SSL probes

Andrew Cooks acooks at gmail.com
Tue Dec 16 03:17:30 UTC 2014


Hi Brad

Not sure what's going on, but I also noticed the probes on ssh. It was
annoying enough that I moved ssh to a different port - not so much for
security, but to stop the constant trickle of spam in my logs and waste of
my ridiculously low dsl bandwidth.

a.

On Tue, Dec 16, 2014 at 11:07 AM, Brad Campbell <brad at fnarfbargle.com>
wrote:

> G'day all,
>
> In the last couple of days we've seen an exponential increase in probes on
> ssh and new hits on imap. Notable because we've never seen the hits on the
> imap server before :
>
> dovecot: imap-login: Disconnected (no auth attempts in 0 secs): user=<>,
> rip=99.56.220.255, lip=192.168.2.1, TLS handshaking: SSL_accept() failed:
> error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol,
> session=<K/n1XR0KQwBjONz/>
>
> Anyone else know what is going on ?
>
> _______________________________________________
> PLUG discussion list: plug at plug.org.au
> http://lists.plug.org.au/mailman/listinfo/plug
> Committee e-mail: committee at plug.org.au
> PLUG Membership: http://www.plug.org.au/membership
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.plug.org.au/pipermail/plug/attachments/20141216/419028e6/attachment.html>


More information about the plug mailing list