Re: I'm getting attacked



Damian 'legion' Szuberski wrote:
On 2007-02-14, jsuthan wrote:

I keep getting logs like these - the x is there to protect the guilty:

Jan 16 05:37:47 penguin sshd[16174]: Invalid user guest from
x.199.53.194
Jan 16 05:37:50 penguin sshd[16176]: Invalid user master from
x.199.53.194
Jan 16 05:37:53 penguin sshd[16178]: Invalid user apache from
x.199.53.194
Jan 16 05:38:15 penguin sshd[16199]: Invalid user admin from
x.199.53.194

Can someone give me advice about what I should do about it? One idea is
to move the ssh port to something besides the default. But really I'm
not sure. Please help.

give attacker some work .. example switch you default ssh port 22 to 44 or something else. Doing this attacker need to sniff out which port your ssh assign to. You also can enable tcpd features; this library enforces system to strict network connectivity. Checkout man page for host.allow and host.deny. Finally something very important learn to use iptables; prime linux security.

One more advice how to obtain security through obscurity?


Admitted - but the script kiddies are dumb enough to
try standard ports only. At least the traffic quieted
totally after I moved out of the standard TCP/22.

--

Tauno Voipio
tauno voipio (at) iki fi
.



Relevant Pages

  • Using SSH without raising questions
    ... I'm looking both for advice and pointers to advice ... My work email was ... default port 22. ... Will it notice that I've got the Bitvise SSH ...
    (comp.security.ssh)
  • Re: ssh library attack
    ... > Everyday someone has attempted to log into my ssh server 1000s of times ... Perhaps I could just change to some obsecure port number? ... tauno voipio iki fi ...
    (comp.os.linux.networking)
  • Re: ssh gives "Permission denied, please try again"
    ... port 22 on your internal machine, so you will need to keep ssh up to ... I configure the router to forward a different external port to 22 on my ... For good measure pick usernames that are none obvious, ... root/password: 163 times ...
    (uk.comp.os.linux)
  • [NEWS] SSH service at Dell DRAC4 Denial of Service (Mocana)
    ... SSH service at Dell DRAC4 Denial of Service ... Dell Remote Access Card 4 allows customers to effectively manage ... After the use of such a port scanner, ...
    (Securiteam)
  • Re: Remote Desktop directly to another computer on the network
    ... default port... ... And there is no reason for me to believe that ssh ... When I have a multibillion company I will use the key pair, ... WinSCP for that to access my home SSH server. ...
    (microsoft.public.windowsxp.work_remotely)