LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices


Reply
  Search this Thread
Old 05-06-2008, 02:46 PM   #1
frenchn00b
Senior Member
 
Registered: Jun 2007
Location: E.U., Mountains :-)
Distribution: Debian, Etch, the greatest
Posts: 2,561

Rep: Reputation: 57
Can hackers easily break regular SSH servers (config with no root access) ?


Hello,
Since hackers are getting very good now, I have been hearing today that some could break SSH servers. I have not idea how but anyway...

Is SSH very unbreakable by hackers (with crazy complex pwd and no root access)?

--
Security is always a thema, particularly for Debian, since Debian runs lot of servers in the world.
 
Old 05-06-2008, 02:54 PM   #2
Dutch Master
Senior Member
 
Registered: Dec 2005
Posts: 1,686

Rep: Reputation: 124Reputation: 124
Ssh is as strong as the password you use it with. It can be broken by 'brute force' attacks, but generally, the ssh-server will deny any logins after 3 failed attempts for a specified timeframe. That buys you time, but not safety. However, most crackers (hackers do thing to prove something, crackers to make money or other evil stuff) don't want to spend hours trying to crack some ssh entry. Overall, using ssh is safe, as VPN's and such are based on ssh too
 
Old 05-06-2008, 03:10 PM   #3
rocket357
Member
 
Registered: Mar 2007
Location: 127.0.0.1
Distribution: OpenBSD-CURRENT
Posts: 485
Blog Entries: 187

Rep: Reputation: 74
SSH that isn't watched closely is a probable target, since it's likely a hacker can spend a bit of time toying with it to crack the password. SSH configured for certificates is more secure (harder to "crack" a certificate than a password), but if a hacker managed to get the certificate...you get the picture.

The purpose of SSH is to allow an administrator remote access to a machine to run commands. Unfortunately, the same functionality is exposed to hackers...and as Dutch Master pointed out, brute force will *always* find the right key given enough time...so the question is not "can it be done", but rather "am I willing to watch closely and monitor SSH to shut down crack attempts before they get out of hand?"

That's a question only you can answer.

Last edited by rocket357; 05-06-2008 at 03:12 PM.
 
Old 05-06-2008, 04:00 PM   #4
frenchn00b
Senior Member
 
Registered: Jun 2007
Location: E.U., Mountains :-)
Distribution: Debian, Etch, the greatest
Posts: 2,561

Original Poster
Rep: Reputation: 57
Quote:
Originally Posted by rocket357 View Post
SSH that isn't watched closely is a probable target, since it's likely a hacker can spend a bit of time toying with it to crack the password. SSH configured for certificates is more secure (harder to "crack" a certificate than a password), but if a hacker managed to get the certificate...you get the picture.

The purpose of SSH is to allow an administrator remote access to a machine to run commands. Unfortunately, the same functionality is exposed to hackers...and as Dutch Master pointed out, brute force will *always* find the right key given enough time...so the question is not "can it be done", but rather "am I willing to watch closely and monitor SSH to shut down crack attempts before they get out of hand?"

That's a question only you can answer.
that hence means to get the right config of :
Code:
fail2ban 
and also the /etc/ssh/sshd_config
?
 
Old 05-06-2008, 04:10 PM   #5
rocket357
Member
 
Registered: Mar 2007
Location: 127.0.0.1
Distribution: OpenBSD-CURRENT
Posts: 485
Blog Entries: 187

Rep: Reputation: 74
I'm not 100% sure I understood your last post, but if I read it correctly, you're asking if fail2ban and a proper sshd config would help? Certainly! I've not much experience with fail2ban, but my understanding is that it "listens" for brute force attempts and injects iptables rules to block those ip addresses. As Dutch Master posted earlier, this is just buying you time, not complete protection.

As for sshd config, keep in mind that turning off root access does NOT protect you from a user in the wheel group using su (or sudo for sudoers). The good thing about turning off root is that now the hacker must guess 2 items instead of 1: the password AND the username. Theoretically it'd take longer to "crack" both the username and the password that matches that username. It has nothing to do with root access (though that part helps haha).

Last edited by rocket357; 05-06-2008 at 04:12 PM.
 
Old 05-06-2008, 11:55 PM   #6
introuble
Member
 
Registered: Apr 2004
Distribution: Debian -unstable
Posts: 700

Rep: Reputation: 31
Quote:
Originally Posted by frenchn00b View Post
Since hackers are getting very good now
Where did you get this information from?
 
Old 05-07-2008, 12:31 AM   #7
aux
LQ Newbie
 
Registered: Feb 2008
Posts: 2

Rep: Reputation: 0
if i'm not mistaken there's a script to exp this one on security focus, good luck.(oh sht, i thought it's to..., sorry my mistake)

Last edited by aux; 05-07-2008 at 12:39 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
root access using SSH atrac Linux - Security 2 10-29-2007 10:05 PM
SSH Root Access DediPlace Linux - Security 6 05-29-2005 11:05 AM
Can root access be gained from regular user account without password? jdruin Linux - Security 5 11-22-2004 10:20 AM
Giving regular users access to certain root-only commands slickrcbd Linux - Newbie 4 12-24-2003 07:27 AM
SSH Config - non-root users toccoa Linux - Newbie 1 07-18-2003 10:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Debian

All times are GMT -5. The time now is 08:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration