LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-17-2020, 12:30 PM   #1
danjde
Member
 
Registered: Jun 2014
Posts: 36

Rep: Reputation: Disabled
Question Strange SSHd log on Debian 10 (VPS)


Hi Friends,
I've just purchased a VPS Linux box, Debian 10.
the first thing i did was to change the ssh port number.
Then I've reload the sshd daemon.

At this point sshd has shows me this log:


Code:
Jan 17 09:55:18 vmi336544.myserver.net sshd[3295]: Disconnected
from authenticating user root 222.186.30.76 port 13081 [preauth]
This log shows only a tentative or an active connection?


Many Thanks!
 
Old 01-17-2020, 12:36 PM   #2
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Doesn't look like an active connection. FYI, the port is irrelevant. A determined attacker will find a service on any port, not just well known ports. Do you have root login via SSH disabled in your config?
 
Old 01-17-2020, 01:26 PM   #3
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,727

Rep: Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211
Quote:
Originally Posted by sevendogsbsd View Post
Doesn't look like an active connection. FYI, the port is irrelevant. A determined attacker will find a service on any port, not just well known ports. Do you have root login via SSH disabled in your config?
I think the operative word here is determined. Using a non-standard port for ssh has reduced the number of failed login attempts on my server from thousands per day to zero.
 
Old 01-17-2020, 01:37 PM   #4
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
Agree, just pointing it out. I see time and time again on the web side where people try to "hide" assets using unknown urls or hosting on other ports and they are 100% of the time, found. An automated script "kiddie" if you will, will only look for well known ports. An actual human that knows what they are doing will look for all 65k ports.

If that works for you, great. It doesn't work for the web side of the gov org I support.
 
1 members found this post helpful.
Old 01-17-2020, 01:44 PM   #5
scasey
LQ Veteran
 
Registered: Feb 2013
Location: Tucson, AZ, USA
Distribution: CentOS 7.9.2009
Posts: 5,727

Rep: Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211Reputation: 2211
Quote:
Originally Posted by sevendogsbsd View Post
Agree, just pointing it out. I see time and time again on the web side where people try to "hide" assets using unknown urls or hosting on other ports and they are 100% of the time, found. An automated script "kiddie" if you will, will only look for well known ports. An actual human that knows what they are doing will look for all 65k ports.

If that works for you, great. It doesn't work for the web side of the gov org I support.
I wouldn't expect any government organization to even allow public-facing ssh access. The last such I worked with used VPN and real-time key* authentication.

*a fob one carried that displayed a login key that changed every 30 seconds. I'm not sure what that was called, but we had to use it every time we logged in, on-site or remotely.
 
Old 01-17-2020, 01:59 PM   #6
sevendogsbsd
Senior Member
 
Registered: Sep 2017
Distribution: FreeBSD
Posts: 2,252

Rep: Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011Reputation: 1011
They don't allow SSH access except through a VPN. I was mainly talking about web hosting: web app owners and web site owners frequently tell us they can hide assets or host the admin page on another port, etc. We tell them security through obscurity is not a valid risk mitigation methodology...

RSA key fobs, used to use those! I use 2 factor all the time now, even personally: google authenticator and yubikey.
 
1 members found this post helpful.
Old 01-17-2020, 02:16 PM   #7
danjde
Member
 
Registered: Jun 2014
Posts: 36

Original Poster
Rep: Reputation: Disabled
Many many thanks to all!!

Davide
 
  


Reply

Tags
security, ssh, sshd



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Starting sshd: /etc/init.d/sshd: line 113: /usr/sbin/sshd: Permission denied sumanc Linux - Server 5 03-28-2008 04:59 AM
Strange sshd log messages sorenp Linux - Security 3 04-19-2007 12:58 PM
FC4-Starting sshd: Privilege separation user sshd does not exist FAILED kiranherekar Fedora 5 12-29-2005 02:22 PM
Enabling SSH in mandrake 9.2 - sshd vs. sshd-xinetd DogTags Linux - Newbie 7 11-25-2003 12:17 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:02 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration