|
Incidents
SSH attacks? Jul 26 2004 10:59PM Robin (robin kallisti net nz) (10 replies) Re: SSH attacks? Jul 28 2004 04:33AM brandy (brandy klammeraffe org) (2 replies) Re: SSH attacks? Jul 29 2004 12:22AM Andrew J Caines (A J Caines halplant com) (3 replies) Re: SSH attacks? Jul 27 2004 09:12PM buzz (reitenba fh-brandenburg de) (2 replies) Re: SSH attacks? Jul 27 2004 08:46PM Adam Young (adam vbfx com) (1 replies) Re: SSH attacks? Jul 28 2004 08:19AM Christine Kronberg (Christine_Kronberg genua de) (3 replies) Re: SSH attacks? Jul 29 2004 09:21AM Pieter-Bas IJdens (pieter-bas ijdens com) (2 replies) |
|
Privacy Statement |
Hash: SHA1
On Thu, 29 Jul 2004, Pieter-Bas IJdens wrote:
> If you are so worried about SSH security who don't you just run sshd on
> a non-standard port.
That practice affords no security benefit. Any scanner worth its
salt (no pun...really) can identify a service even if it's running on a
non-standard port. Nessus does this, as do a host of other scanners.
For my own part, I set my firewall rulesets to default deny any IP
that is not specifically blessed for interactive login. For example, I do
not have any users who live in Asia, Europe, Canada, South America or
Africa. Thus, those netblocks are not allowed to connect on 22/TCP.
This helps limit the attack vectors while still allowing my users access
to the systems they require.
For now, I think we need to spend a little more time getting to
the bottom of *why* we're seeing this uptick in scans. Someone openly
postulated that a distro mirror may have been compromised and the
injection of a trojaned SSHd may be in play. While I don't have any
evidence to support this, a number of the conditions we've seen of late
(same login ID from various IPs across the globe, for instance) does
support this possibility. Now it's up to us to determine the source of
this trojan SSHd and put it out of our misery.
Them's me thoughts.
- -Jay
( ( _______
)) )) .-"There's always time for a good cup of coffee"-. >====<--.
C|~~|C|~~| (>----- Jay D. Dyson -- jdyson (at) treachery (dot) net [email concealed] -----<) | = |-'
`--' `--' `-------- I am the terror of my enemies. --------' `------'
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (TreacherOS)
Comment: See http://www.treachery.net/~jdyson/ for current keys.
iD8DBQFBCZiR6uxsHJ5aYG4RApYKAJ0ZP/8e9eb6W5qEWXGcjtdSOnCDJQCbBU0S
h1smeLNWPRkY9tKJbr/kvVY=
=GqPs
-----END PGP SIGNATURE-----
[ reply ]