Re: sequences in the auth.log

From: Peter C. Lai (sirmoo_at_cowbert.net)
Date: 08/13/04

  • Next message: Gregory Kuhn: "Re: sequences in the auth.log"
    Date: Fri, 13 Aug 2004 14:33:04 -0400
    To: Mohacsi Janos <mohacsi@niif.hu>
    
    

    On Fri, Aug 13, 2004 at 04:14:29PM +0200, Mohacsi Janos wrote:
    > Hi Sandor,
    > You don't have to worry, unless you have user 'test', 'guest',
    > 'admin', 'root' with poor password: typically same or very similar to your
    > accountname. There seems to be a script around the hackers to scan SSH and
    > gain access to poorly configured servers.... Unfortunately they are plenty
    > of badly configured servers. May be you should disable root access via SSH
    > password (only via keys).

    Disabling root login via ssh will still cause 'failed password' entries in
    syslog. (on openssh 3.7 anyway)

    -- 
    Peter C. Lai
    University of Connecticut
    Dept. of Molecular and Cell Biology
    Yale University School of Medicine
    SenseLab | Research Assistant
    http://cowbert.2y.net/
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Gregory Kuhn: "Re: sequences in the auth.log"

    Relevant Pages

    • vr card issues on 6.1-STABLE
      ... After a motherboard failure in a machine, ... ssh to it. ... router, straight to the machine) and gain access that way, which tells ... is to either a) leave a ping running to one of our servers or b) ...
      (freebsd-stable)
    • Re: SSH Blocking
      ... >noticed that a lot of people will try to gain access to these machines ... If you want to elimintate the possibility that one of these scans and/or login ... disable root login to ssh and disable password based logins. ... the private key half of a private/public key pair should consume around 2KB (for ...
      (Debian-User)
    • Re: [SLE] Hacking Question
      ... >> on my server via ssh. ... > to ssh as guest, admin or test you can try changing your ssh port. ... There was talk of a new wave of exploits/viruses that tries to gain access via ...
      (SuSE)
    • Restricting access
      ... locked it down so that only ssh on port 22 is active. ... IP addresses can gain access to the server. ...
      (comp.os.linux.security)
    • changing umask in ssh
      ... I want to be able to set some users' umask to 002 after they login via ssh. ... Do I have to enable UseLogin to do this from login.conf? ... Yale University School of Medicine ...
      (freebsd-questions)