Re: SSH bruteforce attempts from Verizon to "AS17452 Bitstop Inc"

2024-10-31 Thread Neel Chauhan
Good to hear it's not just me. It seems spoofed TCP/IP headers are used on Tor relay IP addresses, hoping to get away with it as "tor traffic" even when they're non-exit relays. I mean running an exit relay from home is a can of worms if you don't have a static IP block and supportive ISP. My

Re: SSH bruteforce attempts from Verizon to "AS17452 Bitstop Inc"

2024-10-31 Thread J. Hellenthal via NANOG
Don't you have some flow data you can analyze for those time frames to see what on your net it transmitting ? If not I'd suggest you set something up and see all outbound traffic to port 22. -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot abo

Re: SSH bruteforce attempts from Verizon to "AS17452 Bitstop Inc"

2024-10-31 Thread Scott Q.
Hi Neel, this might be an interesting read for you: https://delroth.net/posts/spoofed-mass-scan-abuse/ Scott On Thursday, 31/10/2024 at 14:38 Neel Chauhan wrote: Hi, I am a customer of Verizon Fios in NYC and received a very interesting abuse complaint today from ab...@verizon.com. I got S