Full Disclosure mailing list archives
Re: Distributed SSH username/password brute forceattack
From: Vincent Archer <varcher () denyall com>
Date: Wed, 24 Oct 2007 10:03:50 +0200
On Mon, 2007-10-22 at 22:34 +0200, A.L.M.Buxey () lboro ac uk wrote:
Hi,Oct 22 20:36:13 nms sshd[90657]: Failed password for invalid user gopher from 77.46.152.2 port 55120 ssh2user/password authentication for SSH? one way of cleaning up your logs and killing this type of attack is to reconfigure your OpenSSH to only allow key based logins. stopped my 10M+ logfiles straight away (then the apache attacks were easier to see too ;-) )
Be careful about that. Although key-based logins are easier on your logs, they also generate the problem of transitive access to the server. Years ago, one of the boxes I was managing was hacked from the inside: the hacker got an unsecured linux box thru a script-kiddie level hack, and used the key of a local user to get in. Although you can control how the SSH server on your side works, you have no control on people's private keys and thus cannot enforce passphrases on those keys. You can unknowingly lower your security by moving to a key-based login, because some people who would type a password to log-in will not bother securing their passphrases if they are forced to use a private key. -- Vincent ARCHER varcher () denyall com Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Deny All - 23, rue Notre Dame des Victoires - 75002 Paris - France _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Distributed SSH username/password brute force attack Philipp (Oct 22)
- Re: Distributed SSH username/password brute forceattack cybergoth (Oct 22)
- Re: Distributed SSH username/password brute forceattack Valery Marchuk (Oct 22)
- Re: Distributed SSH username/password brute forceattack A . L . M . Buxey (Oct 22)
- Re: Distributed SSH username/password brute forceattack Anders B Jansson (Oct 22)
- Re: Distributed SSH username/password brute forceattack nocfed (Oct 23)
- Re: Distributed SSH username/password brute forceattack Vincent Archer (Oct 24)
- Re: Distributed SSH username/password brute forceattack A . L . M . Buxey (Oct 22)