Updated linkSecurity researchers are warning administrators to secure their servers in the wake of new Secure Shell (SSH) attacks. Researchers at security firm SANS warned that so-called 'brute force' attacks were occurring on a "daily" basis.

The article isn't clear whether this includes OpenSSH. Does anyone have any further knowledge? I haven't seen any advisories for it.

The attacks attempt to guess usernames and passwords in an attempt to compromise the server.

To help guard against the attacks, SANS researcher Daniel Weseman recommended that administrators help guard against the attacks by making both usernames and passwords more difficult for attackers to guess.

"If you are running any SSH server open to the internet, and your usernames and passwords aren't at least 8 characters or so, your box is either owned by now, or about to be," explained Wesemann.

The link for this article located at IT News Australia is no longer available.