LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-11-2017, 03:30 PM   #1
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Woo-hoo! My first "blog post": "Number of Unauthorized Access Attempts: ZERO"


Finally – after all these years – getting around to turning some of my choicest posts here into LQ "blog posts."

(Hey, if I'm gonna become famous, I'd better get started ...)

Here's the Link ...

This post is addressed to "all of you folks who innocently deployed an Internet-facing server and who just-as-innocently hoped to use 'ssh, alone' to control access to it," and who are now being buried with "script-kiddies" who are trying to guess your passwords ... hundreds of times per second.

This post suggests how you can not only "stop them in their tracks," but actually disappear, completely(!) ... ... from their infernal Radar!

Just by implementing an idea that you use every day at work (while trying to hold your briefcase and your Starbucks® at the same time).

... and (oh yeah) another idea borrowed from the Dr. J R R Tolkein's Dwarf-Kings.

Enjoy™!

Last edited by sundialsvcs; 05-11-2017 at 03:41 PM.
 
Old 05-11-2017, 03:43 PM   #2
hydrurga
LQ Guru
 
Registered: Nov 2008
Location: Pictland
Distribution: Linux Mint 21 MATE
Posts: 8,048
Blog Entries: 5

Rep: Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925Reputation: 2925
Nicely written! Bravo.

From someone who has never set up a public-facing server (so excuse the naive question), how would you technically change between using ssh and openvpn if you're actually logged in to the system at the time using the ssh link provided by the server host? Would it not be like sawing off the branch you're sitting on?
 
Old 05-11-2017, 04:06 PM   #3
astrogeek
Moderator
 
Registered: Oct 2008
Distribution: Slackware [64]-X.{0|1|2|37|-current} ::12<=X<=15, FreeBSD_12{.0|.1}
Posts: 6,264
Blog Entries: 24

Rep: Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194Reputation: 4194
Very nicely done!

I have a draft-project-in-progress blog post and learning experience myself, all about the benefits of using your LQ blog and how that use should complement, but not compete with LQ forum posts...

I think I just found another useful example to cite!

One comment: As you add new and useful blog posts, use categorization to organize them! I have found very little use of the blog categorization feature making the job of sifting other's blog posts an obscure task!

More! More!

Last edited by astrogeek; 05-11-2017 at 04:22 PM. Reason: project, learning
 
Old 05-11-2017, 08:27 PM   #4
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,659

Original Poster
Blog Entries: 4

Rep: Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941Reputation: 3941
Quote:
Originally Posted by hydrurga View Post
From someone who has never set up a public-facing server (so excuse the naive question), how would you technically change between using ssh and openvpn if you're actually logged in to the system at the time using the ssh link provided by the server host? Would it not be like sawing off the branch you're sitting on?
From your description, it rather sounds to me like you are presuming a "shared hosting" scenario, where you are merely "buying time" on someone else's Linux box and you have no control over the actual machine. (All that you have is, as you say, "a SSH-link provided by the server host.") This is not my scenario.

("If you live in your own house, out in the country, you can put that new outhouse anywhere you please." However, "if you live in the city, you must poop where they let you!")

My scenario presumes that you are using a virtual machine, or a group of "containers," which is therefore entirely under your control.

Some shared-hosting companies are far-sighted enough to offer OpenVPN, but not too many. (Yet, why on earth are you using "shared hosting," anyway?)

Last edited by sundialsvcs; 05-12-2017 at 09:53 AM.
 
1 members found this post helpful.
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
"Save as Draft" LQ Blog Post frankbell LQ Suggestions & Feedback 4 03-03-2017 09:11 PM
[SOLVED] X: "loading extension glx" "no screens found" "fatal server error" (w/ nvidia driver) Geremia Slackware 7 12-29-2014 11:00 AM
[SOLVED] "net rpc" "failed to connect to ipc$ share on" or "unable to find a suitable server" larieu Linux - General 0 11-09-2014 12:45 AM
LXer: Displaying "MyComputer", "Trash", "Network Servers" Icons On A GNOME Desktop LXer Syndicated Linux News 0 04-02-2007 08:31 AM
"X-MS" cant open because "x-Multimedia System" cant access files at "smb&qu ponchy5 Linux - Networking 0 03-29-2004 11:18 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration