LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 05-30-2005, 09:33 AM   #1
kamtono
LQ Newbie
 
Registered: Sep 2003
Location: Indonesia
Distribution: RedHat Linux
Posts: 14

Rep: Reputation: 0
change SSH to diffrent port


hello all

two month lately i got infected with suckit, SHV4, SHV5 rootkit, and i don't know how to uninstalled or to remove it.I think rename the infected is fine this also happened with SHV4 and SHV5, and that make me to shut down SSH Server

this my questions ?

1. i checked that rootkit (suckit, SHV4, SHV5) with rkhunter and chkrootkit
is remove or rename the folder is enough ?
2. regarding with my SSH Server, change port to 222 (default smoothwall distro)
is it good way ?


thanks for your concerned
 
Old 05-30-2005, 10:19 AM   #2
niknah
Member
 
Registered: Dec 2002
Location: In front of a computer
Distribution: UPS, DHL, FedEx
Posts: 466

Rep: Reputation: 38
If you've gotten a rootkit best upgrade everything, run
"netstat -nap"
and look at the lines 0.0.0.0 LISTEN

and see which programs are listening, and upgrade ALL of those programs to the latest versions. And remove any of those programs that you don't need.

No point removing it if someone can just get in again and put in another rootkit. If someone knows your computer is vunerable it doesn't take long to run a port scan and find port 222.
 
Old 05-30-2005, 04:00 PM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Re: change SSH to diffrent port


1. i checked that rootkit (suckit, SHV4, SHV5) with rkhunter and chkrootkit is remove or rename the folder is enough ?

No. If you've been compromised and a rootkit was installed, then you absolutely need to format and re-install from scratch (not from a backup). Once someone has gained root on your system, it can be extremely hard to identify all changes or backdoors that may have been installed on the system.

2. regarding with my SSH Server, change port to 222 (default smoothwall distro)
is it good way ?

You'll be better off using good paswords and configuring sshd to not allow root logins. Most port scanners now do some form of service interrogation and can identify what services you are running no matter what port you run them on. Changing to an alternate port will however reduce the number of lame sciptkiddie attacks (like brutessh).
 
Old 06-05-2005, 08:28 AM   #4
duliano
Member
 
Registered: Oct 2004
Location: Clayton, NY
Distribution: SuSE Prof 9.1, 9.2, 9.3Pro X86_64 SLES 8 & 9
Posts: 82

Rep: Reputation: 16
Regading your ssh server you can easily change the port by editing the /etc/ssh/sshd_config file

#Port 22
Port 443

restart the sshd

I chose to put mine on 443 because I travel to other companies and in most cases companies block outbound port 22 however they almost never block 443. This enables me to connect to my site right through their firewall. I can even tunnel vnc, samba, etc. as needed.

Hope this helps
 
Old 08-13-2009, 06:24 PM   #5
userzaq1xsw2
LQ Newbie
 
Registered: Aug 2009
Posts: 1

Rep: Reputation: 0
For the benefit of those searching for this solution as of 08-2009:

In smoothwall 3 you would edit /usr/etc/sshd_config
 
Old 08-13-2009, 06:55 PM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
userzaq1xsw2, please don't resurrect dead threads.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ssh change port Longinus Linux - Newbie 14 12-16-2006 03:34 PM
Change ssh port number israel Linux - Software 2 08-30-2006 05:18 AM
can i change the host's ssh port? guardianx Linux - Software 7 07-11-2005 01:47 PM
Change SSH Port? flamesrock Linux - Software 6 10-02-2004 07:12 PM
Able to change port number between telnet and ssh? x5452 Linux - General 3 03-28-2004 05:04 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration