NamePros
Welcome, Guest! Ready to make a name for yourself in the domain business? We welcome both the hobbyist and professional domainer to join the discussion as part of the NamePros community.

Click here to create your profile to start earning reputation for posting, and trader ratings for buying & selling in our free e-marketplace. Build your trader rating with each successful sale. Our system has tracked over 100,000 sales and counting!
FAQ & TOS Register Search Today's Posts Mark Forums Read

Go Back   NamePros.com > Website Development Discussion Forums > Programming > Webmaster Tutorials
Reload this Page GUIDE: How to help prevent SSH attacks

Webmaster Tutorials Instructional webmaster-related how-to's and tutorials.

Advanced Search
0 members in live chat ~  


Closed Thread
 
LinkBack Thread Tools
Old 10-20-2006, 07:26 AM THREAD STARTER               #1 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life

GUIDE: How to help prevent SSH attacks


Hi all,

i thought i would share this guide with everyone. I created it to help people in securing their SSH connection. I will hopefully be adding a second part on other security methods soon.

How to help prevent SSH attacks

Enjoy!

Rick
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
Last edited by rmwebs; 05-10-2007 at 01:15 AM.
RickM is offline  
Old 10-20-2006, 09:14 AM   #2 (permalink)
Senior Member
 
BeZazz's Avatar
Join Date: Aug 2006
Location: Australia
Posts: 1,362
BeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud ofBeZazz has much to be proud of
 




Just to add to what you have there (which was good ) you should really move SSH off the main IP as well
__________________
Dolphins
OMFG!
BeZazz [US/UK] Low Cost Friendly Hosting 33% Discount Coupon 33-NPS
BeZazz is offline  
Old 10-20-2006, 12:18 PM   #3 (permalink)
Senior Member
 
Cyberian's Avatar
Join Date: Apr 2004
Location: Emerald Triangle
Posts: 4,592
Cyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond reputeCyberian has a reputation beyond repute
 

Member of the Month
January 2006Member of the Month
July 2006

Great little TuT there Ricky, good advice and nice step by step.

Nice Add by ethix as well.

Both rep'd.

Cyberian
__________________
Remember who your loyalties are divided between,
and choose for the right reasons who deserves them.
Cyberian is offline  
Old 10-27-2006, 01:48 PM THREAD STARTER               #4 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
Thanks guys - and yes; its always a good idea to move SSH off the main IP, and if possible instead (or as well as) passwords, use IP detection (i.e only let your IP login).

I plan on doing a second part which will focus more on server security as a whole rather than just SSH.

Rick
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Old 10-28-2006, 05:58 AM   #5 (permalink)
NamePros Member
Join Date: Feb 2006
Posts: 114
argh2xxx is an unknown quantity at this point
 



Your way is good, but I also do it this way. To effectively secure your ssh even further, you need to do:

vi /etc/ssh/sshd_config

1) change the #Protocol 2,1 to Protocol 2 (remember to remove the remark since it's a comment)
2) change the PermitRootLogin yes to PermitRootLogin no
3) change the PermitEmptyPasswords no to PermitEmptyPasswords no
4) change Banner /some/path to Banner /etc/issue
argh2xxx is offline  
Old 10-28-2006, 10:02 AM   #6 (permalink)
Account Suspended
Join Date: Oct 2006
Posts: 7
RedNecker is an unknown quantity at this point
 



Thanks cool guide
RedNecker is offline  
Old 10-29-2006, 06:59 AM   #7 (permalink)
Joe
Senior Member
Join Date: Oct 2005
Location: Kent ~ U.K.
Posts: 3,209
Joe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud ofJoe has much to be proud of
 


Save The Children Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009 Help The Homeless - Holiday 2009
nice
rep added

Joe
__________________
Myself and "JackHeskett" are no longer associated with FusedHosting.net. Please pipe all PMs to admin [at] fusedhosting.net.
Joe is offline  
Old 11-07-2006, 07:33 PM   #8 (permalink)
NamePros Member
Join Date: Apr 2006
Posts: 101
Echelon17 is an unknown quantity at this point
 



Hmm, nice tutorial, but no mention of firewalling the SSH port (iptables) or even using the hosts.deny and hosts.allow files to deny/allow access to individual IP's.

Perhaps extend it to cover those too?
__________________
Are you a freelancer?
www.skillsharing.co.uk
Echelon17 is offline  
Old 11-07-2006, 11:45 PM THREAD STARTER               #9 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
I plan on adding a second part which will cover firewalls as well as other methods of securing your server.

Rick
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Old 11-20-2006, 04:10 PM   #10 (permalink)
NamePros Regular
 
-GWS-'s Avatar
Join Date: Jan 2006
Location: OH
Posts: 374
-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light
 




Hello,

I have done most of these things but I am curious as to know if it is working. I took a new server and installed BFD and changed the SSH port (plus other things) but I dont know if it is working. On all my other servers I get about 3-5 emails each a day from BFD saying it is working. But I have gotten no emails from the new one that has SSH on a different port. Can I check to see if it is working just by using the wrong password to log in on the new port? I dont know if I am not getting email because something is not set up right with it or if moving it to a different port has that much of an effect.
__________________
Liquid Shock Games
-GWS- is offline  
Old 11-20-2006, 04:32 PM   #11 (permalink)
NamePros Member
Join Date: Apr 2006
Posts: 101
Echelon17 is an unknown quantity at this point
 



Originally Posted by gemcotechnologies
Hello,
????: NamePros.com http://www.namepros.com/webmaster-tutorials/249129-guide-how-help-prevent-ssh-attacks.html

I have done most of these things but I am curious as to know if it is working. I took a new server and installed BFD and changed the SSH port (plus other things) but I dont know if it is working. On all my other servers I get about 3-5 emails each a day from BFD saying it is working. But I have gotten no emails from the new one that has SSH on a different port. Can I check to see if it is working just by using the wrong password to log in on the new port? I dont know if I am not getting email because something is not set up right with it or if moving it to a different port has that much of an effect.
You aren't getting any warnings to let you know BFD is working, BECAUSE you've changed the SSH port.

Most automated scanners out there looking to crack SSH are going to check on the default port (22), and obviously won't check the others as it's a waste of time. Because you changed port, these scanners aren't hitting your SSH and as a result you're not getting the warnings.

Yes, you can try logging in manually with an incorrect password and this should flag up a warning.
__________________
Are you a freelancer?
www.skillsharing.co.uk
Echelon17 is offline  
Old 11-20-2006, 11:40 PM THREAD STARTER               #12 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
Yep,

as Echelon17 stated. Once you've moved the port you are likely to get very few if any access attempts on the new port as its all done through use of automated bots that spend hours trying to crack the password.
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Old 11-21-2006, 01:37 AM   #13 (permalink)
Senior Member
 
bbalegere's Avatar
Join Date: Jul 2005
Location: Bangalore
Posts: 1,270
bbalegere is just really nicebbalegere is just really nicebbalegere is just really nicebbalegere is just really nicebbalegere is just really nice
 



Rep added.
Bookmarked the link in del.icio.us

Why don't you submit it in digg?
bbalegere is offline  
Old 11-21-2006, 07:20 AM THREAD STARTER               #14 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
Never really thought about that

Will do it now though...thanks for the suggestion
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Old 02-17-2007, 04:07 PM   #15 (permalink)
Account Suspended
Join Date: Sep 2006
Posts: 1,059
YesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to all
 



Nice step-by-step tutorial.

Thanks for sharing.

Rpd!
YesBrilliant is offline  
Old 02-19-2007, 07:56 PM   #16 (permalink)
AzN
is on hiatus
Join Date: May 2006
Posts: 2,449
AzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond repute
 


Find Marrow Donors! Ethan Allen Fund Ethan Allen Fund Ethan Allen Fund Save a Life Save a Life Save a Life Save a Life Save a Life Save a Life VA Tech Memorial VA Tech Memorial VA Tech Memorial VA Tech Memorial Save a Life Save a Life Save a Life
Repped however on Debian Sarge it was /etc/init.d/ssh restart
Great job!
__________________
Currently on hiatus. Back whenever.
AzN is offline  
Old 03-13-2007, 09:18 PM   #17 (permalink)
NamePros Regular
Join Date: Jan 2007
Posts: 241
NewYorkBum has a spectacular aura aboutNewYorkBum has a spectacular aura about
 



if you really paranoid about your ssh, then move to key based authentication on the top of moving ssh to another port AND ip
NewYorkBum is offline  
Old 03-14-2007, 03:29 PM THREAD STARTER               #18 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
Its not a case of being paranoid....its a case of common sense

key based authentication isn't something that most people require....its a good way to secure it....but not a must have.
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Old 03-17-2007, 06:05 AM   #19 (permalink)
NamePros Member
Join Date: Dec 2006
Posts: 48
rahxephon85 is an unknown quantity at this point
 



Great Guide!
rahxephon85 is offline  
Old 03-17-2007, 01:56 PM THREAD STARTER               #20 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
Thanks
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Old 04-02-2007, 07:58 AM   #21 (permalink)
Account Suspended
Join Date: Apr 2007
Location: UK
Posts: 24
eth01 is an unknown quantity at this point
 



If you ever find yourself in the situation of being attacked by a certain person, you can always trace back the IP'S and Subnets.

Then using IPTABLES block it. I have found that most effective.
eth01 is offline  
Old 05-10-2007, 01:15 AM THREAD STARTER               #22 (permalink)
Senior Member
 
RickM's Avatar
Join Date: Sep 2005
Location: Herts, UK
Posts: 3,806
RickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant futureRickM has a brilliant future
 


Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet Animal Cruelty Save a Life
Just a note, the article has moved to HERE...I've updated the link above too...the old link will still redirect to the new one for the time being.
__________________
Disney World Fans - Mobile Apps for your WDW Vacation!
WSDReg - Affordable Domain Registration. Serving NP members since 2006!

Hotel Site Script - 15% Discount for NP members with code 'NPROS'
RickM is offline  
Closed Thread


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools


 
All times are GMT -7. The time now is 12:59 AM.

Domain name forum recommended by Domaining.com Powered by: vBulletin® Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0 Ad Management plugin by RedTyger