[101336] in North American Network Operators' Group
Re: DreamHost Contact?
daemon@ATHENA.MIT.EDU (Robert E. Seastrom)
Mon Dec 31 04:21:59 2007
To: Gregory Hicks <ghicks@cadence.com>
Cc: nanog@merit.edu, mgreb@linode.com
From: "Robert E. Seastrom" <rs@seastrom.com>
Date: Mon, 31 Dec 2007 04:19:09 -0500
In-Reply-To: <86odc7cjnn.fsf@seastrom.com> (Robert E. Seastrom's message of "Mon, 31 Dec 2007 04:12:28 -0500")
Errors-To: owner-nanog@merit.edu
"Robert E. Seastrom" <rs@seastrom.com> writes:
> Gregory Hicks <ghicks@cadence.com> writes:
>
>>> Date: Sun, 30 Dec 2007 21:42:21 -0500
>>> From: Michael Greb <mgreb@linode.com>
>>>
>>> I've got a user sending a lot of UDP traffic to 208.113.189.13 port 22.
>>> This traffic is very likely undesirable and I'd be willing to pull the
>>> plug immediately if I can get confirmation from DreamHost. Failing that
>>
>> Port 22? Isn't that ssh? Doesn't ssh have the capability to forward X or
>> whatever via ssh?
>
> I'm with Gregory here. Between scp and port forwarding, there are
> plenty of explanations for lots of traffic on port 22. What exactly
> leads you to the conclusion that the traffic is "very likely
> undesirable"?
duh, UDP, not TCP. My bad. Yeah, this is a little bit weird.
---rob