I get automated mails from my server at
home produced by logsentry, and this morning's was full of output
from sshd where some idiot had scanned it for about 90 seconds
between midnight and 1am UK time using
Nessus. Of course, I reported it, with
full log extracts to the ISP who own the IP it originated from.
The thing is what sort of idiot uses a tool that, precisely because it's intended to be used for legitimate security auditing identifies itself very clearly to the SSH server like that if they're trying to compromise a remote host? The person responsible for the scan last night should be taken out and shot, not for doing the scan, but for sucking so badly at it.
![[RSS 2.0]](/images/png/rss20.png)
![[RSS 0.91]](/images/png/rss091.png)
![[Blosxom Powered]](/images/png/blosxom.png)
![[Bursledon Parish]](/images/png/bursledon.png)
![[Use openSUSE]](/images/png/opensuse-green.png)
![[Get Firefox]](/images/png/firefox.png)
![[Lib Dems]](/images/png/button_libdems.png)