LinuxQuestions.org
View the Most Wanted LQ Wiki articles.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 04-21-2006, 07:39 PM   #1
dasbooter
Member
 
Registered: Mar 2005
Posts: 122

Rep: Reputation: 15
SSH FreeNX server am I being invaded?


I currently run a FreeNX server on my opensuse box. I have port 22 on the firewall opened so that I can access my system remotely using putty and the NX client. I just now noticed that I have activity on that port in the gkrellm inet diplay plugin (activity that I have not initiated). I shutdown the Freenx server but the activity remained. Clicking on the inet button displayed a connection represented by a few letters and numbers something like ffm4345:1445 (sorry I cant remember exactly the number but it sort of reminded me of the machine address of a NIC).Closing this port on my firewall immediately stopped the activity.My passwords are relatively secure in that they dont appear in any dict and contain a comb. of upper and lower case letters symbols and spaces.Originally having setup cygwin I remember setting up the keys to ssh but I sort of forget how now and I set up FreeNX using the default nomachine key because of all of the horror stories I read about people trying to use there own keys.With putty I just have accepted the key and away I went.I guess a little bit of knowledge is a dangerous thing for me. General googling on the subject reveals a deluge of info could I pls have a bit of direction.

First thing probably is to verify if I have been compromised or not how can I go about doing so?
Secondly I guess I will have to work on securing ssh which seems like it is a rather big subject.

ps. opened the port on my firewall to see if the activity returned while I was at the system and see if I could get that number but of course I dont feel comfortable leaving it down while I am not at the system.The activity has not returned of as yet.
 
Old 04-22-2006, 12:10 PM   #2
ataraxia
Member
 
Registered: Apr 2006
Location: Pittsburgh
Distribution: Debian Sid AMD64
Posts: 296

Rep: Reputation: 30
It's probably people trying to break in via SSH. This happens to me all the time, and if you have good passwords and such, you should be ok. Have a look at some of the logfiles and see if you see any signs that anyone actually managed to break in (I don't know which log SuSE puts SSH output into).
 
Old 04-24-2006, 08:30 AM   #3
ScooterB
Member
 
Registered: Sep 2003
Location: NW Arkansas
Distribution: Linux Redhat 9.0, Fedora Core 2,Debian 3.0, Win 2K, Win95, Win98, WinXp Pro
Posts: 344

Rep: Reputation: 31
You might consider setting up iptables and writing the firewall as if your server was a bastion host. Then everytime you look at your logs, you can close out that ip address if they aren't supposed to be in. If you are wanting real up to the time info, set up Snort as an IDS and then you can find out immediately if someone is trying to get in that isn't supposed to.
 
Old 04-24-2006, 03:34 PM   #4
dasbooter
Member
 
Registered: Mar 2005
Posts: 122

Original Poster
Rep: Reputation: 15
thanks for the replys
I have been able to ascertian so far with
code: #cat /var/log/messages | grep sshd
Apr 21 18:35:53 **** sshd[26118]: Invalid user amanda from 65.205.238.12
Apr 21 18:35:59 **** sshd[26130]: Invalid user amanda from 65.205.238.12
Apr 21 18:36:07 **** sshd[26146]: Invalid user bob from 65.205.238.12
Apr 21 18:36:08 **** sshd[26148]: Invalid user bryan from 65.205.238.12
....etc....
I dont think that they actually got in but it seems to me that there was traffic both ways in the gkrellm monitor?
I have now taken more elaborate precautions to protect myself thanks all
 
Old 04-25-2006, 07:45 AM   #5
ScooterB
Member
 
Registered: Sep 2003
Location: NW Arkansas
Distribution: Linux Redhat 9.0, Fedora Core 2,Debian 3.0, Win 2K, Win95, Win98, WinXp Pro
Posts: 344

Rep: Reputation: 31
You're definitely getting the old dictionary attack. Just block them in your firewall and keep on going. Just watch the logs daily and keep adding the ip addresses of the wirey attackers. It will require diligence and daily maintenance but that is the world of IT. Good luck and have fun!
 
Old 04-25-2006, 06:15 PM   #6
DaveG
Member
 
Registered: Nov 2001
Location: London, UK
Distribution: Fedora 16
Posts: 160

Rep: Reputation: 41
A few more things to consider:
Change from port 22 (ListenAddress). Non-standard and ugly but effective.
Use SSH V2 ONLY (Protocol 2) and disable passwords in favour of RSA keys.
Set up a specific "ssh users" group id and restrict access to users only in that group (AllowGroups) to cut down the number of accounts exposed to dictionary attack.
Take a look at some of the dynamic ssh tarpit/blacklist scripts around for iptables.
 
Old 04-26-2006, 04:30 AM   #7
Yoss
LQ Newbie
 
Registered: Apr 2003
Posts: 17

Rep: Reputation: 0
You can use an portknocking tool.
http://www.portknocking.org

regards
Yoss
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Passwordless SSH with SSH commercial server and open ssh cereal83 Linux - General 7 04-18-2006 12:34 PM
setup freenx ssh blocked meping Linux - Software 2 04-13-2006 06:39 PM
LXer: HOWTO Install FreeNX Server on SUSE 10 LXer Syndicated Linux News 3 03-21-2006 06:54 PM
Nomachine/freenx server netcrusher88 Debian 1 12-14-2005 02:53 AM
freeNX terminal server ape Linux - Software 0 11-23-2004 05:00 AM


All times are GMT -5. The time now is 04:40 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration