LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 03-17-2014, 05:43 AM   #1
raiak
LQ Newbie
 
Registered: Mar 2014
Posts: 1

Rep: Reputation: Disabled
SSH Banner function


Hi

I would like to send a banner to a client after 2 failed password attempts. I know how to send a banner before authentication and after authentication. But I don't know if I can send a banner at any time I want, in my case after 2 failed password.

thanks in advance!!
 
Old 03-17-2014, 12:39 PM   #2
MensaWater
LQ Guru
 
Registered: May 2005
Location: Atlanta Georgia USA
Distribution: Redhat (RHEL), CentOS, Fedora, CoreOS, Debian, FreeBSD, HP-UX, Solaris, SCO
Posts: 7,831
Blog Entries: 15

Rep: Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669Reputation: 1669
I'd suggest you do NOT want to do that.

If someone bad is trying to hack your system you do NOT want to give them clues as to WHY they are being unsuccessful. This is why most system just tell you "login failed" rather than "invalid user" or "invalid password". No point in telling them which part they GUESSED correctly.

If you really do want to do it anyway you could probably muck with pam modules to do what you want.
 
1 members found this post helpful.
Old 03-17-2014, 01:43 PM   #3
szboardstretcher
Senior Member
 
Registered: Aug 2006
Location: Detroit, MI
Distribution: GNU/Linux systemd
Posts: 4,278

Rep: Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694Reputation: 1694
Agreed.

I display a scary warning message before the prompt. I stole this off of Centos or Redhat a long time ago.

Quote:
WARNING : Unauthorized access to this system is forbidden and will be
prosecuted by law. By accessing this system, you agree that your actions
may be monitored if unauthorized usage is suspected.
Dont ever tell a user what they are doing wrong with regards to login attempts. If you really want something informative,.. make a message that says 'see systems administrator'.
 
Old 03-17-2014, 07:53 PM   #4
padeen
Member
 
Registered: Sep 2009
Location: Perth, W.A.
Distribution: Slackware, Debian, Gentoo, FreeBSD, OpenBSD
Posts: 208

Rep: Reputation: 41
I don't want to give a standard banner that uniquely identifies me, so I have a cron script that writes generic output, such as the output of `fortune`, to a banner file every day. Ssh uses that banner.

The idea is that an IP scanner will never receive output that uniquely identifies me. They can still get me from the IP address of course, but nothing from a file containing several million IP addresses and output that they can grep.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to disable SSH version banner ? dlugasx Linux - Security 7 12-31-2013 02:08 AM
ssh banner and motd binary_dreamer Debian 4 04-14-2013 06:03 PM
hide ssh banner shafey Linux - Security 3 04-14-2013 05:59 PM
SSH banner design garnser Linux - Software 1 10-16-2004 02:07 AM
change the banner for ssh [cacheflow] Linux - Security 5 09-16-2002 03:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 07:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration