LinuxQuestions.org
Support LQ: Use code LQCO20 and save 20% on CrossOver Office
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 05-19-2005, 09:57 AM   #1
naomi
LQ Newbie
 
Registered: Jan 2005
Posts: 7

Rep: Reputation: 0
ssh man-in-the-middle


pls help me!!.. an acquaintance used ssh login to victimize me in a man-in-the-middle attack. i know it was just for fun but is there some way i could protect myself from it or better yet maybe teach me how to do it

i know this is out of character... but i want revenge

i'm currently using fedora core 3 in a small network of around 16 computers

i looked around the net trying to figure out man-in-the-middle but to no avail (sigh)
 
Old 05-19-2005, 12:04 PM   #2
freakyg
Member
 
Registered: Apr 2005
Distribution: LFS 5.0 and 6.1
Posts: 705

Rep: Reputation: 30
I found this FAQ..............

http://www.onsight.com/faq/ssh/ssh-faq-1.html

Quote:
1.12 . Shouldn't I be using only SSH2?

Maintainer's note: Since this brought up an interesting discussion on the mailing list, it seems to be a good idea to incorporate some of the helpful information that folks brought up. Thanks! Also, if someone has a better way to organize this section, please let me know.

The SSH1 protocol is not being developed anymore, as SSH2 is being developed as the standard. Even if you are not using SSH2, many folks are establishing a path towards it. With three implementations (and growing) of SSH2 currently in the works, there is growing support (especially with the SSH2 protocol in IETF draft). However, there are arguments for and against running SSH1.

Note: If you have any additional arguments either way, I'll post them. -AC

* There are structural weaknesses in SSH1 which leave it open to additional attacks
* SSH1 is subject to a man-in-the-middle attack
* SSH1 has more supported platforms
* SSH1 supports .rhosts authentication (it's against the draft for SSH2
* SSH1 has more diverse authentication support (AFS, Kerberos, etc.)
* Performance for SSH2 is not equal to SSH1
 
Old 05-19-2005, 02:04 PM   #3
Dr. Psy
Member
 
Registered: May 2005
Distribution: Slackware 10.1
Posts: 49

Rep: Reputation: 15
SSH man in the middle attack can be done with dnsspoof and sshmitm, included in the Dsniff package

http://www.monkey.org/~dugsong/dsniff/

As a side note, when someone on your network attempts this, you should recieve the notice below when attempting to SSH into a remote machine. If you have not changed anything recently in regards to SSH, and get this message, it may indicate an SSH man-in-the-middle attack. If that's the case, then drop the log in, and investigate the possible attack.

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@ WARNING: HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@

IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now
(man-in-the-middle attack)! It is also possible that
the host-key has just been changed. Please contact
your system administrator.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
man in the middle attack atul_mehrotra Programming 12 09-22-2004 11:48 AM
man in the middle attack atul_mehrotra Linux - Security 4 09-22-2004 09:02 AM
Man in the middle attack juanb Linux - Security 17 03-29-2004 01:03 PM
MAN page formatting incorrect via telnet/SSH pederslie Linux - Newbie 3 12-11-2002 02:35 AM
Compiling packages on RH 7.1 causes man files to be named man.gz mmboam Linux - General 0 05-09-2001 06:47 PM


All times are GMT -5. The time now is 04:41 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration