LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-13-2024, 02:52 PM   #1
englishexe
LQ Newbie
 
Registered: Jan 2024
Posts: 1

Rep: Reputation: 0
Exclamation /etc/issue.net print out a warning message to sshed users & log their ip


So I have just installed Debian Linux (CLI) onto a spare laptop acting as a mini server and to "scare" off intruders I want to output something along the lines of:
Code:
===========================================================
---          Unauthorised Access Is Prohibited          ---
--- It is against the law to secure unauthorised access ---
---             (Computers Misuse Act 1990)             ---
===========================================================
This connection has been logged. (\4)

= Metrics =
Users logged in: \u

= Machine =
Debian 12 (\s) (v\r)
The issue I'm noticing is that when physically using the computer it outputs correctly with the correct information but when SSHing in (tried pUTTY and normal Windows Command line) it outputs the literal text ("\u" instead of ("1") how can I fix this?

I also would like to save the user's IP in a file so I can block them from my network if they attempt to log in

Thanks
 
Old 01-13-2024, 03:48 PM   #2
michaelk
Moderator
 
Registered: Aug 2002
Posts: 25,766

Rep: Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933Reputation: 5933
Why would you want to display any sort of information except for the warning message prior to login? Did you configure the banner in the sshd_config for /etc/issue.net? Not that any warning will scare off any sort of bot.

Is ssh only available on your LAN or is it also available over the internet?

ssh login information including IP address is located in the /var/log/auth.log.
 
Old 01-13-2024, 04:15 PM   #3
boughtonp
Senior Member
 
Registered: Feb 2007
Location: UK
Distribution: Debian
Posts: 3,619

Rep: Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555Reputation: 2555

That header is pointless.

Install fail2ban.

 
Old 01-15-2024, 11:41 AM   #4
jayjwa
Member
 
Registered: Jul 2003
Location: NY
Distribution: Slackware, Termux
Posts: 795

Rep: Reputation: 254Reputation: 254Reputation: 254
As I recall, ssh doesn't parse what's in the Banner setting in sshd_config. /etc/issue is for local logins, parsed by a/getty; /etc/issue.net is for remote. 99.9% of the hits against a sshd are bots. You are wasting time and CPU cycles chasing ghosts with IP bans. People rent out VPSs, do their dirt, and get their accounts closed in a number of days. The next customer gets that IP and the ssh scanner is gone on to another IP and the cycle continues. Use key login only and forget about it. The days of one user = one set IP are long gone.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to log internal-sftp chroot jailed users access log to /var/log/sftp.log file LittleMaster Linux - Server 0 09-04-2018 03:45 PM
How read only users from Nagios can see only their hostgroup along with their hosts mrwlad Linux - Server 6 10-02-2012 09:16 AM
Japanese canna won't work : Warning: かな漢字変&am OrganicOrange84 Debian 3 06-30-2005 02:28 PM
Phục hồi dữ liệu bị mất???, cứ pollsite General 1 06-27-2005 12:39 PM
Gotta love those ٱٱٱٱٱٱٱ&# iLLuSionZ Linux - General 5 11-18-2003 07:14 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:18 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration