Re: sshd warning---a lil' help?

From: Kevin Kinsey, DaleCo, S.P. (kdk@daleco.biz)
Date: 04/10/02


From: "Kevin Kinsey, DaleCo, S.P." <kdk@daleco.biz>
To: <peter.lai@uconn.edu>
Date: Wed, 10 Apr 2002 01:59:24 -0500

Thanks to all 3 of you and esp. Mr. Lai......

I had always been fairly sure of 'a' ... but was hoping 'c' to also be the
case
until today when a situation arose that prompted the post. The login
attempt entry
I quoted was a successful one from a trusted machine. Made me wonder if any
of the other ones
I'd seen in the past from unknown locations/networks might have also
authenticated.

As of yet, no signs of intrusion .... but my security skills are still in
the 'growing' stage.

KDK

----- Original Message -----
From: "Peter C. Lai" <sirmoo@cowbert.2y.net>
To: "Kevin Kinsey, DaleCo, S.P." <kdk@daleco.biz>
Cc: <security@FreeBSD.ORG>
Sent: Tuesday, April 09, 2002 5:50 PM
Subject: Re: sshd warning---a lil' help?

> a is true. the message is coming from hosts.allow, which checks for rdns
as
> a (weak) signal of spoofed packets. You can deny these connections by
> by turning on:
>
> ALL : PARANOID : RFC931 20 : deny
> # Provide some protection against clients using a forged source IP address
>
>
> b would have sshd report "password" or keypair "accepted for username".
>
> c would have shown that user being rejected
>
> consequently, we don't know from what you've given us to know
> if someone logged in successfully to sshd runing with pid 34375
> at that time :)
>
> On Tue, Apr 09, 2002 at 08:03:02AM -0500, Kevin Kinsey, DaleCo, S.P.
wrote:
> > Apr 9 07:50:00 elisha sshd[34375]: warning: /etc/hosts.allow, line 23:
> > can't verify hostname: getaddrinfo(gbrdialin, AF_INET$) Failed
> >
> > This computer ---
> >
> > a - has incorrect or NO reverse DNS ?
> > b - tried to authenticate via ssh login and succeeded?
> > c - tried to authenticate via ssh login and failed?
> > d - other
> >
> >
> > TIA, Kevin Kinsey
> >
> >
> >
> >
> > To Unsubscribe: send mail to majordomo@FreeBSD.org
> > with "unsubscribe freebsd-security" in the body of the message
>
> --
> Peter C. Lai
> University of Connecticut
> Dept. of Residential Life | Programmer
> Dept. of Molecular and Cell Biology | Undergraduate Research Assistant
> http://cowbert.2y.net/
> 860.427.4542 (Room)
> 860.486.1899 (Lab)
> 203.206.3784 (Cellphone)
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Linux authentication via AD
    ... What I do to integrate with Windows is to use NIS and Samba. ... a way to do this under older AIX) allows people to login authenticating ... authentication is done to the Windows Password Server. ... text passwords authenticate to the Windows Password Server as well. ...
    (comp.os.linux.security)
  • Re: Was told by DSL tech support that
    ... Network Setup Wizard"? ... PPPoE does not in itself require a login and password. ... PBI/SBC/AT&T wants the user to authenticate. ...
    (alt.internet.wireless)
  • Re: Linux authentication via AD
    ... Primarily I need to integrate Linux ... servers, but I do have a few OpenBSD servers. ... > a way to do this under older AIX) allows people to login authenticating ... > text passwords authenticate to the Windows Password Server as well. ...
    (comp.os.linux.security)
  • Re: Unexplained Failed Logins
    ... We do audit successful logins. ... failures were a backup job at 11:58 pm and a NAV scan at 5:00 am. ... if the DC is attempting a login via a delegation, ... and directly attempt Kerberos authN on network exposed ...
    (microsoft.public.win2000.security)
  • not authenticating when redirected from another page
    ... target page, it first checks to see if the user/browser is authenticated. ... the page I wanted after a successful login. ... authenticate, it sends the login page back again. ... even though I'm using the same browser window. ...
    (microsoft.public.dotnet.framework.aspnet)