[advanced search]
Results from the most recent live auction are here.
17 members in the live chat room. Join Chat!
Register Rules & FAQ NP$ Store Active Threads Mark Forums Read
Go Back   NamePros.Com > Design and Development > Webmaster Tutorials
User Name
Password

Old 10-20-2006, 07:26 AM   · #1
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Arrow GUIDE: How to help prevent SSH attacks

Hi all,

i thought i would share this guide with everyone. I created it to help people in securing their SSH connection. I will hopefully be adding a second part on other security methods soon.

How to help prevent SSH attacks

Enjoy!

Rick


Please register or log-in into NamePros to hide ads
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!

Last edited by rmwebs : 05-10-2007 at 01:15 AM.
RickM is offline   Reply With Quote
Old 10-20-2006, 09:14 AM   · #2
ethix
Senior Member
 
ethix's Avatar
 
Location: Australia
Trader Rating: (29)
Join Date: Aug 2006
Posts: 1,140
NP$: 137.80 (Donate)
ethix is a splendid one to beholdethix is a splendid one to beholdethix is a splendid one to beholdethix is a splendid one to beholdethix is a splendid one to beholdethix is a splendid one to beholdethix is a splendid one to behold
Just to add to what you have there (which was good ) you should really move SSH off the main IP as well
ethix is offline   Reply With Quote
Old 10-20-2006, 12:18 PM   · #3
~ Cyberian ~
CyberianDomains
 
~ Cyberian ~'s Avatar
 
Name: Cy
Location: SoCal
Trader Rating: (66)
Join Date: Apr 2004
Posts: 3,846
NP$: 13.00 (Donate)
~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute~ Cyberian ~ has a reputation beyond repute
Member of the Month
January 2006Member of the Month
July 2006
Great little TuT there Ricky, good advice and nice step by step.

Nice Add by ethix as well.

Both rep'd.

Cyberian
__________________
Share your knowledge, it's a way to achieve Immortality.
~ Cyberian ~ is offline  
  Reply With Quote
Old 10-27-2006, 01:48 PM   · #4
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Thanks guys - and yes; its always a good idea to move SSH off the main IP, and if possible instead (or as well as) passwords, use IP detection (i.e only let your IP login).

I plan on doing a second part which will focus more on server security as a whole rather than just SSH.

Rick
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Old 10-28-2006, 05:58 AM   · #5
argh2xxx
NamePros Member
 
Trader Rating: (0)
Join Date: Feb 2006
Posts: 112
NP$: 0.00 (Donate)
argh2xxx is an unknown quantity at this point
Your way is good, but I also do it this way. To effectively secure your ssh even further, you need to do:

vi /etc/ssh/sshd_config

1) change the #Protocol 2,1 to Protocol 2 (remember to remove the remark since it's a comment)
2) change the PermitRootLogin yes to PermitRootLogin no
3) change the PermitEmptyPasswords no to PermitEmptyPasswords no
4) change Banner /some/path to Banner /etc/issue
argh2xxx is offline   Reply With Quote
Old 10-28-2006, 10:02 AM   · #6
RedNecker
Account Closed
 
Trader Rating: (0)
Join Date: Oct 2006
Posts: 7
NP$: 0.00 (Donate)
RedNecker is an unknown quantity at this point
Thanks cool guide
RedNecker is offline   Reply With Quote
Old 11-07-2006, 07:33 PM   · #8
Echelon17
NamePros Member
 
Trader Rating: (0)
Join Date: Apr 2006
Posts: 101
NP$: 0.00 (Donate)
Echelon17 is an unknown quantity at this point
Hmm, nice tutorial, but no mention of firewalling the SSH port (iptables) or even using the hosts.deny and hosts.allow files to deny/allow access to individual IP's.

Perhaps extend it to cover those too?
__________________
Are you a freelancer?
www.skillsharing.co.uk
Echelon17 is offline   Reply With Quote
Old 11-07-2006, 11:45 PM   · #9
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
I plan on adding a second part which will cover firewalls as well as other methods of securing your server.

Rick
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Old 11-20-2006, 04:10 PM   · #10
-GWS-
NamePros Regular
 
Name: Mark
Location: OH
Trader Rating: (40)
Join Date: Jan 2006
Posts: 373
NP$: 2477.50 (Donate)
-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light-GWS- is a glorious beacon of light
Hello,

I have done most of these things but I am curious as to know if it is working. I took a new server and installed BFD and changed the SSH port (plus other things) but I dont know if it is working. On all my other servers I get about 3-5 emails each a day from BFD saying it is working. But I have gotten no emails from the new one that has SSH on a different port. Can I check to see if it is working just by using the wrong password to log in on the new port? I dont know if I am not getting email because something is not set up right with it or if moving it to a different port has that much of an effect.
__________________
Buy Domains | Sell Domains The Domain Dealers - List your names for sale free.
Elyria Businesses
-GWS- is offline  
  Reply With Quote
Old 11-20-2006, 04:32 PM   · #11
Echelon17
NamePros Member
 
Trader Rating: (0)
Join Date: Apr 2006
Posts: 101
NP$: 0.00 (Donate)
Echelon17 is an unknown quantity at this point
Originally Posted by gemcotechnologies
Hello,

I have done most of these things but I am curious as to know if it is working. I took a new server and installed BFD and changed the SSH port (plus other things) but I dont know if it is working. On all my other servers I get about 3-5 emails each a day from BFD saying it is working. But I have gotten no emails from the new one that has SSH on a different port. Can I check to see if it is working just by using the wrong password to log in on the new port? I dont know if I am not getting email because something is not set up right with it or if moving it to a different port has that much of an effect.



You aren't getting any warnings to let you know BFD is working, BECAUSE you've changed the SSH port.

Most automated scanners out there looking to crack SSH are going to check on the default port (22), and obviously won't check the others as it's a waste of time. Because you changed port, these scanners aren't hitting your SSH and as a result you're not getting the warnings.

Yes, you can try logging in manually with an incorrect password and this should flag up a warning.
__________________
Are you a freelancer?
www.skillsharing.co.uk
Echelon17 is offline   Reply With Quote
Old 11-20-2006, 11:40 PM   · #12
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Yep,

as Echelon17 stated. Once you've moved the port you are likely to get very few if any access attempts on the new port as its all done through use of automated bots that spend hours trying to crack the password.
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Old 11-21-2006, 01:37 AM   · #13
bbalegere
Senior Member
 
Name: Bharat Balegere
Location: Bangalore
Trader Rating: (15)
Join Date: Jul 2005
Posts: 1,178
NP$: 9.25 (Donate)
bbalegere is just really nicebbalegere is just really nicebbalegere is just really nicebbalegere is just really nice
Rep added.
Bookmarked the link in del.icio.us

Why don't you submit it in digg?
bbalegere is offline   Reply With Quote
Old 11-21-2006, 07:20 AM   · #14
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Never really thought about that

Will do it now though...thanks for the suggestion
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Old 02-17-2007, 04:07 PM   · #15
YesBrilliant
Account Closed
 
Trader Rating: (21)
Join Date: Sep 2006
Posts: 1,075
NP$: 0.00 (Donate)
YesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to allYesBrilliant is a name known to all
Nice step-by-step tutorial.

Thanks for sharing.

Rpd!
YesBrilliant is offline   Reply With Quote
Old 02-19-2007, 07:56 PM   · #16
AzN
Is away for a while.
 
AzN's Avatar
 
Location: San Francisco, CA
Trader Rating: (105)
Join Date: May 2006
Posts: 2,454
NP$: 277.00 (Donate)
AzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond reputeAzN has a reputation beyond repute
Find Marrow Donors! Ethan Allen Fund Ethan Allen Fund Ethan Allen Fund Save a Life Save a Life Save a Life Save a Life Save a Life Save a Life VA Tech Memorial VA Tech Memorial VA Tech Memorial VA Tech Memorial Save a Life Save a Life Save a Life
Repped however on Debian Sarge it was /etc/init.d/ssh restart
Great job!
__________________
My Portfolio: ServiceInteract Creatives
Shrink your URLs with URLShrinker.net!
For all hosting info, HostReports.com
I recommend TheHiveDesigns and Fucian Tech for web design services.
AzN is offline   Reply With Quote
Old 03-13-2007, 09:18 PM   · #17
NewYorkBum
NamePros Regular
 
Trader Rating: (7)
Join Date: Jan 2007
Posts: 228
NP$: 11.00 (Donate)
NewYorkBum has a spectacular aura aboutNewYorkBum has a spectacular aura about
if you really paranoid about your ssh, then move to key based authentication on the top of moving ssh to another port AND ip
NewYorkBum is offline   Reply With Quote
Old 03-14-2007, 03:29 PM   · #18
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Its not a case of being paranoid....its a case of common sense

key based authentication isn't something that most people require....its a good way to secure it....but not a must have.
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Old 03-17-2007, 06:05 AM   · #19
rahxephon85
NamePros Member
 
Trader Rating: (0)
Join Date: Dec 2006
Posts: 44
NP$: 2.00 (Donate)
rahxephon85 is an unknown quantity at this point
Great Guide!
rahxephon85 is offline   Reply With Quote
Old 03-17-2007, 01:56 PM   · #20
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Thanks
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Old 04-02-2007, 07:58 AM   · #21
eth01
Account Closed
 
Name: Tom Markey
Location: UK
Trader Rating: (0)
Join Date: Apr 2007
Posts: 24
NP$: 0.00 (Donate)
eth01 is an unknown quantity at this point
If you ever find yourself in the situation of being attacked by a certain person, you can always trace back the IP'S and Subnets.

Then using IPTABLES block it. I have found that most effective.
eth01 is offline   Reply With Quote
Old 05-10-2007, 01:15 AM   · #22
RickM
www.RickyMills.com
 
RickM's Avatar
 
Name: Rick Mills
Location: Herts, UK
Trader Rating: (93)
Join Date: Sep 2005
Posts: 3,609
NP$: 1460.52 (Donate)
RickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud ofRickM has much to be proud of
Cancer Survivorship Save The Children Save The Children Cancer Animal Cruelty Child Abuse Cancer Survivorship 9/11/01 :: Never Forget Animal Cruelty Child Abuse Animal Rescue Animal Cruelty Protect Our Planet Protect Our Planet Protect Our Planet
Just a note, the article has moved to HERE...I've updated the link above too...the old link will still redirect to the new one for the time being.
__________________
$7.99 .MOBI Registration! • Entrepreneur & Tech Blog • Webmaster Community

Accepting offers on: (pm or visit my site)
LWWH*com | SwitchMy*com | NetworkMOBI*com | MLLK*net | +Lots of LL-L.com domains!
RickM is offline   Reply With Quote
Closed Thread

NamePros is a revenue sharing forum.

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump