LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-09-2005, 09:16 AM   #1
sniff
Member
 
Registered: Jan 2003
Location: Durham UK
Distribution: openSUSE/Debian/ubuntu
Posts: 362

Rep: Reputation: 42
Hacks against ssh


Hello,
Somebody or bodies are trying to hack into my server. All it does is ftp and ssh and people are trying to hack into it via ssh. In the system log there are long lists of failed login attempts with different user names. I have beefed up all the passwords, and made sure that there is no root login. Should I be doing anything else.

Something else that has started to happen is that external access to the server, ie not from the network has suddenly got very slow. But from within the network is fine. Can anyone think why this might be, the upload/download seems to be the same as before and I can surf the net from the server without problems.

Cheers,
Phil
 
Old 12-09-2005, 09:18 AM   #2
nx5000
Senior Member
 
Registered: Sep 2005
Location: Out
Posts: 3,307

Rep: Reputation: 57
http://www.linuxquestions.org/questi...d.php?t=340366
 
Old 12-09-2005, 09:24 AM   #3
sniff
Member
 
Registered: Jan 2003
Location: Durham UK
Distribution: openSUSE/Debian/ubuntu
Posts: 362

Original Poster
Rep: Reputation: 42
Hi
Thanks for that, I should have look more carefully but its the first time I have been hacked. Exciting stuff Looks like this tool is being used on me also. About every two days it would seem.

Cheers,
Phil
 
Old 12-09-2005, 12:45 PM   #4
int0x80
Member
 
Registered: Sep 2002
Posts: 310

Rep: Reputation: Disabled
You're not necessarily being compromised each time the attack ensues. Check your /var/log/auth.log to see if there are any unauthorized logins.
 
Old 12-14-2005, 08:13 AM   #5
sniff
Member
 
Registered: Jan 2003
Location: Durham UK
Distribution: openSUSE/Debian/ubuntu
Posts: 362

Original Poster
Rep: Reputation: 42
No, your right. I should have said, "its first time someones attempted to hack my server". As the person appears to have failed. This tool they are using that tests a list of names didn't get the login.

Cheers,
Phil
 
Old 12-14-2005, 09:41 AM   #6
sundialsvcs
LQ Guru
 
Registered: Feb 2004
Location: SE Tennessee, USA
Distribution: Gentoo, LFS
Posts: 10,665
Blog Entries: 4

Rep: Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945Reputation: 3945
As others have said, the strongest defense is to disallow password logins completely, using only digital certificates.

If you don't have a badge, you can't come in. And there's no way for you to "fake" a badge.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Favorite scripts and hacks? SocialEngineer Programming 4 02-23-2005 10:15 AM
Help with Linux Server Hacks book: Turbo-mode SSH logins ToBe Linux - Security 4 12-21-2003 11:39 AM
too many hacks running now !?! virgin Linux - Newbie 1 07-05-2003 08:38 PM
Audio hacks Freaksta Linux - General 1 06-26-2003 02:13 PM
Hollywood hacks P2P! bripage General 6 08-05-2002 10:32 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration