<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>LOL Bruteforce von Microsoft Netz</title>
    <link>http://forum.geizhals.at/feed.jsp?id=871959</link>
    <description>Geizhals-Forum</description>
    <item>
      <title>Re(2): LOL Bruteforce von Microsoft Netz</title>
      <link>http://forum.geizhals.at/t871959,7552631.html#7552631</link>
      <description>Eher ein Virus auf einem System in der Cloud.&lt;br&gt;Trotzdem cool. Ein Bruteforce Angrif von Microsoft.&lt;br/&gt;</description>
      <pubDate>Sat, 14 Nov 2015 13:31:33 GMT</pubDate>
      <guid>http://forum.geizhals.at/t871959,7552631.html#7552631</guid>
      <dc:creator>MG</dc:creator>
      <dc:date>2015-11-14T13:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: LOL Bruteforce von Microsoft Netz</title>
      <link>http://forum.geizhals.at/t871959,7552593.html#7552593</link>
      <description>Jo mei, wird sihc wer bei MS vertippt haben beim Anlegen eines Zugangs. Wenn's Dir wichtig ist, schick's halt dem MS-CERT, Adresse steht eh da.&lt;br/&gt;</description>
      <pubDate>Sat, 14 Nov 2015 13:07:43 GMT</pubDate>
      <guid>http://forum.geizhals.at/t871959,7552593.html#7552593</guid>
      <dc:creator>Fly</dc:creator>
      <dc:date>2015-11-14T13:07:43Z</dc:date>
    </item>
    <item>
      <title>LOL Bruteforce von Microsoft Netz</title>
      <link>http://forum.geizhals.at/t871959,7552591.html#7552591</link>
      <description>Hi,&lt;br&gt;&lt;br&gt;The IP 137.116.87.13 has just been banned by Fail2Ban after&lt;br&gt;6 attempts against ssh.&lt;br&gt;&lt;br&gt;&lt;br&gt;Here are more information about 137.116.87.13:&lt;br&gt;&lt;br&gt;&lt;br&gt;#&lt;br&gt;# ARIN WHOIS data and services are subject to the Terms of Use&lt;br&gt;# available at: &lt;a href="https://www.arin.net/whois_tou.html" rel="noopener" target="_blank"&gt;https:/&lt;wbr/&gt;/&lt;wbr/&gt;www.arin.net/&lt;wbr/&gt;whois_tou.html&lt;/a&gt; &lt;br&gt;#&lt;br&gt;# If you see inaccuracies in the results, please report at&lt;br&gt;# &lt;a href="http://www.arin.net/public/whoisinaccuracy/index.xhtml" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;www.arin.net/&lt;wbr/&gt;public/&lt;wbr/&gt;whoisinaccuracy/&lt;wbr/&gt;index.xhtml&lt;/a&gt; &lt;br&gt;#&lt;br&gt;&lt;br&gt;&lt;br&gt;#&lt;br&gt;# The following results may also be obtained via:&lt;br&gt;# &lt;a href="http://whois.arin.net/rest/nets;q=137.116.87.13?showDetails=true&amp;showARIN=false&amp;showNonArinTopLevelNet=false&amp;ext=netref2" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;whois.arin.net/&lt;wbr/&gt;rest/&lt;wbr/&gt;nets;q=137.116.87.13?&lt;wbr/&gt;showDetails=true&amp;&lt;wbr/&gt;showARIN=false&amp;&lt;wbr/&gt;showNonArinTopLevelNet=false&amp;&lt;wbr/&gt;ext=netref2&lt;/a&gt; &lt;br&gt;#&lt;br&gt;&lt;br&gt;NetRange:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 137.116.0.0 - 137.116.255.255&lt;br&gt;CIDR:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 137.116.0.0/16&lt;br&gt;NetName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;MICROSOFT&lt;br&gt;NetHandle:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;NET-137-116-0-0-1&lt;br&gt;Parent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET137 (NET-137-0-0-0-0)&lt;br&gt;NetType:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Direct Assignment&lt;br&gt;OriginAS:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br&gt;Organization:&amp;nbsp;&amp;nbsp; Microsoft Corp (MSFT-Z)&lt;br&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2011-08-02&lt;br&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2013-08-20&lt;br&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://whois.arin.net/rest/net/NET-137-116-0-0-1" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;whois.arin.net/&lt;wbr/&gt;rest/&lt;wbr/&gt;net/&lt;wbr/&gt;NET-137-116-0-0-1&lt;/a&gt; &lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;OrgName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Microsoft Corp&lt;br&gt;OrgId:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;MSFT-Z&lt;br&gt;Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;One Microsoft Way&lt;br&gt;City:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Redmond&lt;br&gt;StateProv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;WA&lt;br&gt;PostalCode:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 98052&lt;br&gt;Country:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;US&lt;br&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2011-06-22&lt;br&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2015-10-28&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;To report suspected security issues specific to &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;traffic emanating from Microsoft online services, &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;including the distribution of malicious content &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;or other illicit or illegal material through a &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Microsoft online service, please submit reports &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;to:&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;* &lt;a href="https://cert.microsoft.com" rel="noopener" target="_blank"&gt;https:/&lt;wbr/&gt;/&lt;wbr/&gt;cert.microsoft.com&lt;/a&gt; .&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;For SPAM and other abuse issues, such as Microsoft &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Accounts, please contact:&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;* abuse@microsoft.com.&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;To report security vulnerabilities in Microsoft &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;products and services, please contact:&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;* secure@microsoft.com.&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;For legal and law enforcement-related requests, &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;please contact:&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;* msndcc@microsoft.com&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;For routing, peering or DNS issues, please &lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;contact:&lt;br&gt;Comment:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;* IOC@microsoft.com&lt;br&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://whois.arin.net/rest/org/MSFT-Z" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;whois.arin.net/&lt;wbr/&gt;rest/&lt;wbr/&gt;org/&lt;wbr/&gt;MSFT-Z&lt;/a&gt; &lt;br&gt;&lt;br&gt;&lt;br&gt;OrgAbuseHandle: MAC74-ARIN&lt;br&gt;OrgAbuseName:&amp;nbsp;&amp;nbsp; Microsoft Abuse Contact&lt;br&gt;OrgAbusePhone:&amp;nbsp;&amp;nbsp;+1-425-882-8080 &lt;br&gt;OrgAbuseEmail:&amp;nbsp;&amp;nbsp;abuse@microsoft.com&lt;br&gt;OrgAbuseRef:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://whois.arin.net/rest/poc/MAC74-ARIN" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;whois.arin.net/&lt;wbr/&gt;rest/&lt;wbr/&gt;poc/&lt;wbr/&gt;MAC74-ARIN&lt;/a&gt; &lt;br&gt;&lt;br&gt;OrgTechHandle: MRPD-ARIN&lt;br&gt;OrgTechName:&amp;nbsp;&amp;nbsp; Microsoft Routing, Peering, and DNS&lt;br&gt;OrgTechPhone:&amp;nbsp;&amp;nbsp;+1-425-882-8080 &lt;br&gt;OrgTechEmail:&amp;nbsp;&amp;nbsp;IOC@microsoft.com&lt;br&gt;OrgTechRef:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;a href="http://whois.arin.net/rest/poc/MRPD-ARIN" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;whois.arin.net/&lt;wbr/&gt;rest/&lt;wbr/&gt;poc/&lt;wbr/&gt;MRPD-ARIN&lt;/a&gt; &lt;br&gt;&lt;br&gt;&lt;br&gt;#&lt;br&gt;# ARIN WHOIS data and services are subject to the Terms of Use&lt;br&gt;# available at: &lt;a href="https://www.arin.net/whois_tou.html" rel="noopener" target="_blank"&gt;https:/&lt;wbr/&gt;/&lt;wbr/&gt;www.arin.net/&lt;wbr/&gt;whois_tou.html&lt;/a&gt; &lt;br&gt;#&lt;br&gt;# If you see inaccuracies in the results, please report at&lt;br&gt;# &lt;a href="http://www.arin.net/public/whoisinaccuracy/index.xhtml" rel="noopener" target="_blank"&gt;http:/&lt;wbr/&gt;/&lt;wbr/&gt;www.arin.net/&lt;wbr/&gt;public/&lt;wbr/&gt;whoisinaccuracy/&lt;wbr/&gt;index.xhtml&lt;/a&gt; &lt;br&gt;#&lt;br&gt;&lt;br&gt;&lt;br&gt;Lines containing IP:137.116.87.13 in /var/log/auth.log&lt;br&gt;&lt;br&gt;Nov 14 12:51:57 d018 sshd[47081]: Did not receive identification string from 137.116.87.13&lt;br&gt;Nov 14 12:52:03 d018 sshd[47082]: Invalid user buchhaltung from 137.116.87.13&lt;br&gt;Nov 14 12:52:03 d018 sshd[47082]: Connection closed by 137.116.87.13 [preauth]&lt;br&gt;Nov 14 12:52:09 d018 sshd[47084]: Invalid user empfang from 137.116.87.13&lt;br&gt;Nov 14 12:52:09 d018 sshd[47084]: Connection closed by 137.116.87.13 [preauth]&lt;br&gt;Nov 14 12:52:15 d018 sshd[47086]: Invalid user dr from 137.116.87.13&lt;br&gt;Nov 14 12:52:15 d018 sshd[47086]: Connection closed by 137.116.87.13 [preauth]&lt;br&gt;Nov 14 12:52:20 d018 sshd[47088]: Invalid user pascal from 137.116.87.13&lt;br&gt;Nov 14 12:52:20 d018 sshd[47088]: Connection closed by 137.116.87.13 [preauth]&lt;br&gt;Nov 14 12:52:26 d018 sshd[47090]: Invalid user pflege from 137.116.87.13&lt;br&gt;Nov 14 12:52:26 d018 sshd[47090]: Connection closed by 137.116.87.13 [preauth]&lt;br&gt;Nov 14 12:52:32 d018 sshd[47092]: Invalid user scan from 137.116.87.13&lt;br&gt;Nov 14 12:52:32 d018 sshd[47092]: Connection closed by 137.116.87.13 [preauth]&lt;br&gt;&lt;br&gt;&lt;br&gt;Regards,&lt;br&gt;&lt;br&gt;Fail2Ban&lt;br/&gt;</description>
      <pubDate>Sat, 14 Nov 2015 13:05:26 GMT</pubDate>
      <guid>http://forum.geizhals.at/t871959,7552591.html#7552591</guid>
      <dc:creator>MG</dc:creator>
      <dc:date>2015-11-14T13:05:26Z</dc:date>
    </item>
  </channel>
</rss>
