atom feed13 messages in org.freebsd.freebsd-securityReality check: IPFW sees SSH traffic ...
FromSent OnAttachments
David WolfskillMar 21, 2007 12:45 pm 
Tadas MiniotasMar 21, 2007 1:18 pm 
David WolfskillMar 21, 2007 1:32 pm 
Bill MoranMar 21, 2007 1:37 pm 
Richard JonesMar 21, 2007 2:12 pm 
Dan LukesMar 21, 2007 2:27 pm 
Bill MoranMar 21, 2007 2:29 pm 
W. D.Mar 21, 2007 2:44 pm 
Eygene RyabinkinMar 21, 2007 2:50 pm 
Julian ElischerMar 21, 2007 11:21 pm 
Carl MakinMar 21, 2007 11:22 pm 
VolkerMar 22, 2007 1:32 pm 
Eygene RyabinkinMar 23, 2007 11:36 am 
Subject:Reality check: IPFW sees SSH traffic that sshd does not?
From:Tadas Miniotas (tad@bofh.lt)
Date:Mar 21, 2007 1:18:10 pm
List:org.freebsd.freebsd-security

David Wolfskill wrote:

<...> This morning (in reviewing the logs from yesterday), I found a set of 580 such setup requests logged from Mar 20 19:30:06 - Mar 20 19:40:06 (US/Pacific; currently 7 hrs. west of GMT/UTC), each from 204.11.235.148 (part of a VAULT-NETWORKS netblock). The sshd on the internal machine never logged anything corresponding to any of this.

Might be a SYN scan. I believe SSH will not log anything if a three-way handshake has not been completed.

Of course, it would help if you provided ipfw logs to determine exactly what kind of packets it was.