LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 10-06-2005, 08:50 AM   #1
michaelsanford
Member
 
Registered: Feb 2005
Location: Ottawa/Montréal
Distribution: Slackware + Darwin (MacOS X)
Posts: 468

Rep: Reputation: 30
ssh login reverse mapping failed, should I worry?


Code:
Address 67.71.152.11 maps to 10.152.71.61.in-addr.arpa, but this
does not map back to the address - POSSIBLE BREAKIN ATTEMPT!
I just got this when logging in to my Slackware box from my campus wifi (first time I've used the campus wifi, new system). Could that be the culprit?

PS 67.71.152.11 is the address of my server as reported by ifconfig | grep ppp0.
 
Old 10-06-2005, 04:44 PM   #2
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
It just means that the reverse DNS for your campus wifi is not properly configured and SSH could not determine a hostname for the IP in question. Personally, I don't know why SSH gripes about this, but I'm sure there is a (somewhat) legitimate reason somewhere.
 
Old 10-06-2005, 05:34 PM   #3
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 47
From the sshd_config manpages
Quote:
UseDNS Specifies whether sshd should lookup the remote host name
and check that the resolved host name for the remote IP
address maps back to the very same IP address.
The default is "yes"

Last edited by ppuru; 10-06-2005 at 05:36 PM.
 
Old 10-16-2005, 09:27 AM   #4
michaelsanford
Member
 
Registered: Feb 2005
Location: Ottawa/Montréal
Distribution: Slackware + Darwin (MacOS X)
Posts: 468

Original Poster
Rep: Reputation: 30
I had a feeling it was UseDNS, but I'm never sure whether it's the sshd or ssh that outputs those messages (i.e., I wasn't totally sure whether it was my end or the server end that was complaining about the DNS entry being wrong).

Thanks.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Failed SSH login attempts Capt_Caveman Linux - Security 38 01-03-2006 03:22 PM
Failed Login through SSH? Help PLEASE tangman Linux - Newbie 8 03-31-2004 03:02 PM
ssh failed login question nelly_boy Solaris / OpenSolaris 3 02-26-2004 08:52 AM
ssh failed login count - where is it? mbhenry Linux - Security 1 11-13-2003 11:35 AM
reverse zone mapping ssrikant Linux - Networking 2 04-28-2003 01:32 PM


All times are GMT -5. The time now is 05:03 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration