Linux Format forums Forum Index Linux Format forums
Help, discussion, magazine feedback and more
 
 FAQFAQ   SearchSearch   MemberlistMemberlist   UsergroupsUsergroups   RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 

ssh attack

 
Post new topic   Reply to topic    Linux Format forums Forum Index -> Discussion
View previous topic :: View next topic  
Author Message
RD
LXF regular


Joined: Mon Jul 25, 2005 3:53 am
Posts: 272
Location: irc.ixl2.net

PostPosted: Mon Sep 19, 2005 1:28 pm    Post subject: ssh attack Reply with quote

Hi

today i looked at my system logs (main auth.log) and found that there has been 6 ssh attempts on my computer Shocked none of which have got in Very Happy

it would seem from the auth.log that they are using a dictionary mounted attack (god help them if there using John as that is use less still has not broken my password since LXF 71 was released). So im posting just to say check you auth.log see if there are any ssh connections to your box i dont know if these attacks are from a company/script kiddie or other
Back to top
View user's profile Send private message Visit poster's website
nelz
Site admin


Joined: Mon Apr 04, 2005 12:52 pm
Posts: 8364
Location: Warrington, UK

PostPosted: Mon Sep 19, 2005 4:14 pm    Post subject: RE: ssh attack Reply with quote

It happens all the time. the safest approach is to disable password logins to SSH, limiting it to key authorisations only.
_________________
"Insanity: doing the same thing over and over again and expecting different results." (Albert Einstein)
Back to top
View user's profile Send private message
RD
LXF regular


Joined: Mon Jul 25, 2005 3:53 am
Posts: 272
Location: irc.ixl2.net

PostPosted: Mon Sep 19, 2005 4:58 pm    Post subject: RE: ssh attack Reply with quote

i have Smile, thanks any way just thought i would let ever one know maybe they can see if there system has been attacked like mine
_________________
[url=irc://irc.ixl2.org/ixl2]irc.ixl2.org[/url]
Back to top
View user's profile Send private message Visit poster's website
nordle
LXF regular


Joined: Fri Apr 08, 2005 10:56 pm
Posts: 1500

PostPosted: Mon Sep 19, 2005 9:43 pm    Post subject: RE: ssh attack Reply with quote

I don't know realistically how much extra security it gives, but you can change:

1. Only allow ssh version 2 connections
2. Change the AllowUsers section to only include an internal IP range
3. Change the default port number from 22

As well as the key access, I have no idea if these are any good or not, just some notes I've got.
_________________
I think, therefore I compile
Back to top
View user's profile Send private message
RD
LXF regular


Joined: Mon Jul 25, 2005 3:53 am
Posts: 272
Location: irc.ixl2.net

PostPosted: Mon Sep 19, 2005 11:57 pm    Post subject: RE: ssh attack Reply with quote

Thanks nordle but if i was that worried id simply stop the port on my router and stop sshd untill needed Smile
_________________
[url=irc://irc.ixl2.org/ixl2]irc.ixl2.org[/url]
Back to top
View user's profile Send private message Visit poster's website
View previous topic :: View next topic  
Display posts from previous:   
Post new topic   Reply to topic    Linux Format forums Forum Index -> Discussion All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
Linux Format forums topic RSS feed 


Powered by phpBB © 2001, 2005 phpBB Group


Copyright 2011 Future Publishing, all rights reserved.


Web hosting by UKFast