nixCraft Linux Forum

nixCraft

Linux / UNIX Tech Support Forum

Failed SSH login attempts and how to avoid brute ssh attacks

This is a discussion on Failed SSH login attempts and how to avoid brute ssh attacks within the Networking, Firewalls and Security forums, part of the Mastering Servers category; Originally Posted by monk Originally Posted by B!n@ry Ohhhh, man all from scratch ???? what a head ache Sure it ...


Go Back   nixCraft Linux Forum > Mastering Servers > Networking, Firewalls and Security

Linux answers from nixCraft.


Networking, Firewalls and Security No it's not a secret. Talk about firewalls and security issues.

Reply

 

LinkBack Thread Tools Display Modes
  #11 (permalink)  
Old 20-12-2006, 03:48 AM
B!n@ry's Avatar
Senior Member
User
 
Join Date: Dec 2006
Location: B!n@ry-z0ne
OS: Ojuba 3
Posts: 129
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
B!n@ry
Send a message via MSN to B!n@ry
Default

Quote:
Originally Posted by monk
Quote:
Originally Posted by B!n@ry
Ohhhh, man all from scratch ???? what a head ache
Sure it is a pain but sometime you have to write everything from scratch. If you are setting up a cluster or complicated networking APF or other scripts are not useful.

And not to mention you can make some good money by providing customized solution
Yep monk you are right with every word thats why these days I am consintrating on iptables, but really its not easy.

by the way thanx for locating me to a job
__________________
LivE Free 0r DiE
L!nux rul3z aLL
Reply With Quote
  #12 (permalink)  
Old 20-12-2006, 03:49 AM
B!n@ry's Avatar
Senior Member
User
 
Join Date: Dec 2006
Location: B!n@ry-z0ne
OS: Ojuba 3
Posts: 129
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
B!n@ry
Send a message via MSN to B!n@ry
Default

Quote:
Originally Posted by nixcraft

@monk
Buddy don't give us our secrets in public making money is not bad I guess :P
Hello nixCraft,
sharing knowledge here is also part of sharing money man
__________________
LivE Free 0r DiE
L!nux rul3z aLL
Reply With Quote
  #13 (permalink)  
Old 20-12-2006, 03:51 AM
B!n@ry's Avatar
Senior Member
User
 
Join Date: Dec 2006
Location: B!n@ry-z0ne
OS: Ojuba 3
Posts: 129
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
B!n@ry
Send a message via MSN to B!n@ry
Default

Quote:
Originally Posted by sweta
Quote:
Originally Posted by Bin@ry
nixCraft, its not a "find" its installed on our Servers
LOL ... do u have your own box for learning or for business??? I think nixcrat is not using any sort of CP just a guess

Bye
No I have more than 1 b0x, most of them are for business, WEB HOSTING COMPANY.
Thanx for ur wonderful quotes
__________________
LivE Free 0r DiE
L!nux rul3z aLL
Reply With Quote
  #14 (permalink)  
Old 20-12-2006, 04:11 AM
nixcraft's Avatar
Never say die
User
 
Join Date: Jan 2005
Location: BIOS
OS: RHEL
Scripting language: Bash and Python
Posts: 2,710
Thanks: 11
Thanked 245 Times in 184 Posts
Rep Power: 10
nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute
Default

regrading money ... it was a joke.

Also some SSH stuff is already written by me (in case if anybody wants to read more )

OpenSSH Root user account restriction - revisited : http://www.cyberciti.biz/tips/openss...revisited.html

Linux PAM configuration that allows or deny login via the sshd server: http://www.cyberciti.biz/tips/linux-...hd-server.html

OpenSSH deny or restrict access to users and groups : http://www.cyberciti.biz/tips/openss...nd-groups.html

Force OpenSSH (sshd) to listen on selected multiple IP address only : http://www.cyberciti.biz/tips/howto-...p-address.html
__________________
Vivek Gite
Linux Evangelist
Be proud RHEL user, and let the world know about your enterprise choices! Join RedHat user group.
Always use CODE tags for posting system output and commands!
Do you run a Linux? Let's face it, you need help
Reply With Quote
  #15 (permalink)  
Old 20-12-2006, 12:03 PM
B!n@ry's Avatar
Senior Member
User
 
Join Date: Dec 2006
Location: B!n@ry-z0ne
OS: Ojuba 3
Posts: 129
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
B!n@ry
Send a message via MSN to B!n@ry
Default

w0w u've written all that ? MaN u r amazing
__________________
LivE Free 0r DiE
L!nux rul3z aLL
Reply With Quote
  #16 (permalink)  
Old 20-12-2006, 02:53 PM
rockdalinux's Avatar
Is that all you got?
User
 
Join Date: May 2005
Location: Planet Vegeta
OS: Redhat
Posts: 708
Thanks: 15
Thanked 19 Times in 18 Posts
Rep Power: 10
rockdalinux is a glorious beacon of light rockdalinux is a glorious beacon of light rockdalinux is a glorious beacon of light rockdalinux is a glorious beacon of light rockdalinux is a glorious beacon of light rockdalinux is a glorious beacon of light
Default

Guys send some more tips ... keep 'em comming
__________________
Rocky Jr.
What's wrong? I hope I am not making you uncomfortable...

Never send a boy to do a mans job.
Reply With Quote
  #17 (permalink)  
Old 12-12-2007, 02:46 AM
Junior Member
User
 
Join Date: Dec 2007
OS: RedHat
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
puyursu is on a distinguished road
Default

port knocking it is a solution for hideing ssh port.
Reply With Quote
  #18 (permalink)  
Old 11-03-2009, 03:58 PM
nix's Avatar
nix nix is offline
Junior Member
User
 
Join Date: Feb 2007
Location: Pune, India
OS: Redhat, Sun Solaris
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
nix
Default

Use DenyHosts - Welcome to DenyHosts
Reply With Quote
  #19 (permalink)  
Old 11-02-2010, 08:47 AM
Junior Member
User
 
Join Date: Dec 2008
OS: CentOS
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
spot15 is on a distinguished road
Default

Quote:
Originally Posted by nix View Post
Use DenyHosts - Welcome to DenyHosts
DenyHosts does a good job and is very easy to setup and use (decent amount of options for flexibility).

Also, though I agree with turning off password authentication, if you want to take it one step further, you should still provide a pass-phrase to protect your private key(s).
Reply With Quote
  #20 (permalink)  
Old 12-02-2010, 11:45 AM
vamsi's Avatar
Senior Member
User
 
Join Date: Nov 2009
Location: Bangalore / India
OS: Ubuntu , Debian Lenny , CentOS 5.x
Posts: 109
Thanks: 70
Thanked 7 Times in 5 Posts
Rep Power: 1
vamsi will become famous soon enough
Default

Hi , many say to allow ssh logins' only from 1 IP, but as my ip adress is Dynamic, is there any solution for it ?
__________________
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads

Thread Thread Starter Forum Replies Last Post
to avoid recommended memory message in RHEL token CentOS / RHEL / Fedora 0 22-04-2008 07:08 AM
dovecot: pop3-login: pop3-login: error while loading shared libraries: libsepol.so.1 raj Mail Servers 1 15-11-2007 10:43 AM
avoid displaying errors while executing a script vikas027 Shell scripting 4 31-10-2007 11:57 AM
Linux / UNIX set increase the number of failed login retries with SSH client sweta Getting started tutorials 0 12-06-2007 02:35 AM
Apache SYN Flood Attacks and how to stop / avoid them cbzee Web servers 1 21-12-2006 03:30 AM


All times are GMT +5.5. The time now is 10:26 PM.


Powered by vBulletin® Version 3.8.5 - Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
©2005-2010 nixCraft. All rights reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38