LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-09-2014, 12:15 AM   #1
rwilcher
Member
 
Registered: Mar 2006
Location: Maple Heights OHIO
Distribution: Centos 6
Posts: 31

Rep: Reputation: 0
Angry possible SSH dictionary attacks.


I used to get constant ssh probes. I think it's a dictionary attack.
bad guys run nmap or something similar and and find that you have
a ssh port open. When I used iptables to block access to the port
to all but specific ip addresses it stopped. If I need to remotely
access the machine from a specific location, I only allow that
locations IP in on that port. Seeing all those failed attempts
to ssh in is unnerving to say he least. It appears that if the
port is closed to everyone but who I choose, probes by bad guys
are unproductive and they stop. YMMV but it worked for me. Down
side is having to change iptables to allow things in that you want in.
 
Old 10-09-2014, 12:27 AM   #2
evo2
LQ Guru
 
Registered: Jan 2009
Location: Japan
Distribution: Mostly Debian and CentOS
Posts: 6,724

Rep: Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705Reputation: 1705
Hi,

IMHO, disabling password authentication is the best protection from attempts to brute force a password.

Evo2.
 
Old 10-09-2014, 12:31 AM   #3
rwilcher
Member
 
Registered: Mar 2006
Location: Maple Heights OHIO
Distribution: Centos 6
Posts: 31

Original Poster
Rep: Reputation: 0
Best if you can avoid them getting to a prompt in the first place.
 
Old 10-09-2014, 04:48 AM   #4
TenTenths
Senior Member
 
Registered: Aug 2011
Location: Dublin
Distribution: Centos 5 / 6 / 7
Posts: 3,475

Rep: Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553Reputation: 1553
Consider fail2ban and automatically block an IP for a period of time if there are too many login attempts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Slow ssh attacks david1941 Linux - Security 8 11-29-2009 06:17 PM
SSH attacks, a new approach david1941 Linux - Security 10 09-13-2008 01:16 PM
stopping dictionary attacks whovian Linux - Newbie 4 07-14-2006 03:12 AM
LXer: Preventing SSH Dictionary Attacks With DenyHosts LXer Syndicated Linux News 0 02-19-2006 11:01 AM
Stopping span that are dictionary attacks PDT816 Linux - Security 11 11-10-2004 02:21 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:49 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration