maandag 13 juli 2009

Watson Research Center ssh scan

# grep "129.34.3.3" /var/log/messages
Jul 11 15:31:50 meij sshd[19894]: Failed password for root from 129.34.3.3 port 35477 ssh2
Jul 11 15:31:51 meij sshd[19896]: Failed password for root from 129.34.3.3 port 35702 ssh2
Jul 11 15:31:52 meij sshd[19898]: Failed password for root from 129.34.3.3 port 35873 ssh2
Jul 11 15:31:53 meij sshd[19900]: Failed password for root from 129.34.3.3 port 36003 ssh2
Jul 11 15:31:54 meij sshd[19902]: Failed password for root from 129.34.3.3 port 36177 ssh2
Jul 11 15:31:55 meij sshd[19904]: Failed password for root from 129.34.3.3 port 36332 ssh2
Jul 11 15:31:57 meij sshd[19906]: Failed password for root from 129.34.3.3 port 36462 ssh2
Jul 11 15:31:57 meij denyhosts: Added the following hosts to /etc/hosts.deny - 129.34.3.3 (vserv.watson.ibm.com)
Jul 11 15:31:58 meij sshd[19913]: Failed password for root from 129.34.3.3 port 36666 ssh2
Jul 11 15:31:59 meij sshd[19915]: Failed password for root from 129.34.3.3 port 36795 ssh2
Jul 11 15:32:00 meij sshd[19917]: Failed password for root from 129.34.3.3 port 36937 ssh2
Jul 11 15:32:01 meij sshd[19919]: Failed password for root from 129.34.3.3 port 37086 ssh2
Jul 11 15:32:02 meij sshd[19921]: Failed password for root from 129.34.3.3 port 37215 ssh2
Jul 11 15:32:03 meij sshd[19923]: Failed password for root from 129.34.3.3 port 37333 ssh2
Jul 11 15:32:04 meij sshd[19925]: Invalid user oracle from 129.34.3.3
Jul 11 15:32:04 meij sshd[19925]: Failed password for invalid user oracle from 129.34.3.3 port 37454 ssh2
Jul 11 15:32:05 meij sshd[19927]: Invalid user test from 129.34.3.3
Jul 11 15:32:05 meij sshd[19927]: Failed password for invalid user test from 129.34.3.3 port 37538 ssh2

Unfortunatly there is more amiss at IBM's Watson Research Center:

The original message was received at Mon, 13 Jul 2009 09:11:05 -0400
from
spamguru010.watson.ibm.com [9.2.250.70]

----- The following addresses had permanent fatal errors -----
<
nrt@watson.ibm.com>
(reason: 550 Host unknown)

----- Transcript of session follows -----
554 5.0.0 Service
smokum@gmail.com unknown
550 5.1.2 <
nrt@watson.ibm.com>... Host unknown (Name server: -f: host not found)

Final-Recipient: RFC822;
nrt@watson.ibm.com
X-Actual-Recipient: RFC822;
nrt@mailhub4.watson.ibm.com
Action: failed
Status: 5.1.2
Remote-MTA: DNS; -f
Diagnostic-Code: X-Unix; 550 Host unknown
Last-Attempt-Date: Mon, 13 Jul 2009 09:11:06 -0400

So I guess they'll need to read this blog to find out about their issues ;)
Good luck