LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-29-2011, 07:13 PM   #1
fred49
LQ Newbie
 
Registered: Mar 2009
Posts: 6

Rep: Reputation: 0
Welcome to the Twilight Zone: SSH logging in with NO AUTHENTICATION


I just had a Twilight Zone experience! I was just setting up ssh on my desktop machine and got the wrong path in the -i parameter (identity file) my server is set for "PermitRootLogin without-password", which as I under stand it disables the password login only. I did NOT get the pass phrase prompt and got error message to the effect of key file not found.
and then I got a functional ssh connection to my server!

I had previously been using PUTTY and it too would connect without an identify file!!!!!!!

After a bit of panic a reboot of my DESKTOP machine that I was running the ssh client on the problem went away???. (The server was NOT rebooted although it had been rebooted the day before)

I gotta wonder if I have been compromised -- does anybody have any idea whats going on???

I know that PUTTY has a mechanism to remember identity files and log you in automatically without needing passwords but I had not run it, and why would it also affect ssh???

Last edited by fred49; 09-29-2011 at 07:20 PM.
 
Old 09-29-2011, 07:35 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Posting lines, from the server, wherever SSH logs to and sshd_config (as in 'grep ^# /path/to/file|grep .;') and from the client your botched command line and your ~/.ssh/config may shed a light on things. Apart from that root shouldn't be allowed login over any network so you're not adhering to best practices regardless of your question. If this is a remote server I strongly suggest you correct that before doing anything else.

As far as detecting compromised binaries: your distribution (which?) may or may not have package management tools to help you. If it doesn't and if you haven't set up file integrity checking (Samhain, Aide or even tripwire) then compare package contents with a known good package downloaded from a trusted repository?
 
Old 10-01-2011, 06:03 PM   #3
fred49
LQ Newbie
 
Registered: Mar 2009
Posts: 6

Original Poster
Rep: Reputation: 0
Resolved

End of panic attack.

Apparently gnome_keyring daemon runs by default in Ubuntu. It also appears to work with putty. I sure don't mind computers being helpful, but it sure would be nice if they'd let you know when THEY are helping , , , as opposed to a hacker. what threw me was that it was working with putty and I knew that I wasn't using pageant!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
configure ssh authentication using password file and sftp/scp authentication using ld cameliab Linux - Software 1 08-29-2011 03:28 AM
Bind Query Logging per Zone? archangel_617b Linux - Server 1 03-04-2009 08:28 AM
scp without authentication and ssh with authentication? bkcreddy17 Linux - Server 7 10-08-2008 01:33 AM
Authentication Problem when logging as a non root user sashi_jk Linux - Software 2 06-28-2007 12:57 AM
[SSH] Issue logging in [SSH & Permissions] MD3 Linux - Networking 11 12-10-2006 09:25 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration