public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] SSH authentication attempts - serious issue
@ 2006-06-05 15:06 Leandro Melo de Sales
  2006-06-05 15:27 ` Oliver Schmidt
                   ` (3 more replies)
  0 siblings, 4 replies; 17+ messages in thread
From: Leandro Melo de Sales @ 2006-06-05 15:06 UTC (permalink / raw
  To: gentoo-user

Hi,

   today when I was checking the server log I got many external
attempts to connect to my sshd service:

...
Jun  5 05:09:45 embedded sshd[4740]: Invalid user barbara from x.y.w.z
Jun  5 05:09:46 embedded sshd[4742]: Invalid user barb from x.y.w.z
Jun  5 05:09:48 embedded sshd[4744]: Invalid user barbie from x.y.w.z
Jun  5 05:09:50 embedded sshd[4746]: Invalid user barbra from x.y.w.z
Jun  5 05:09:51 embedded sshd[4748]: Invalid user barman from x.y.w.z
Jun  5 05:09:53 embedded sshd[4750]: Invalid user barney from x.y.w.z
...

this seems to be a brute force attack, but one thing that worried me
is why sshd didn't disconnect the remote host after 3 unsuccessful
attemps? If we see in the log, there are many attemps with time
interval between attemps of 2 or 3 seconds meaning that the sshd
didn't disconnect the remote host after 3 attempts.
 So, first, Am I thinking correct about the sshd attempts?
 Second, how can I setup sshd or the entire system to permit just 2 or
3 attempts of authentication? I was checking the /etc/login.defs file
and I see the following option:

#
# Max number of login retries if password is bad
#
LOGIN_RETRIES           3

but why this didn't work for the above connection attempts?

Thank you,

Leandro.
-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 17+ messages in thread
* RE: [gentoo-user] SSH authentication attempts - serious issue
@ 2006-06-05 16:36 CR Little
  0 siblings, 0 replies; 17+ messages in thread
From: CR Little @ 2006-06-05 16:36 UTC (permalink / raw
  To: gentoo-user

Do Programs like denyhosts work with other protocols? Such as POP or
FTP?

-----Original Message-----
From: Joseph [mailto:syscon@interbaun.com] 
Sent: Monday, June 05, 2006 11:32 AM
To: gentoo-user@lists.gentoo.org
Subject: Re: [gentoo-user] SSH authentication attempts - serious issue

Try port knocking.  It is very effective.
Your ssh port will be closed until you successfully hit certain number
of ports and even though the ssh port will be open only to the IP
address that successfully opened the port all others will see ssh port
as closed.

-- 
#Joseph

On Mon, 2006-06-05 at 12:06 -0300, Leandro Melo de Sales wrote:
> Hi,
> 
>    today when I was checking the server log I got many external
> attempts to connect to my sshd service:
> 
> ...
> Jun  5 05:09:45 embedded sshd[4740]: Invalid user barbara from x.y.w.z
> Jun  5 05:09:46 embedded sshd[4742]: Invalid user barb from x.y.w.z
> Jun  5 05:09:48 embedded sshd[4744]: Invalid user barbie from x.y.w.z
> Jun  5 05:09:50 embedded sshd[4746]: Invalid user barbra from x.y.w.z
> Jun  5 05:09:51 embedded sshd[4748]: Invalid user barman from x.y.w.z
> Jun  5 05:09:53 embedded sshd[4750]: Invalid user barney from x.y.w.z
> ...

-- 
gentoo-user@gentoo.org mailing list




This message contains information from SourceLink - Madison 
which may be confidential and privileged.  If you are not an 
intended recipient, please refrain from any disclosure, copying, 
distribution, or use of this information and note that such 
actions are prohibited.  If you have received this transmission 
in error, please notify by email it-support@sourcelinkmadison.com.


-- 
gentoo-user@gentoo.org mailing list



^ permalink raw reply	[flat|nested] 17+ messages in thread

end of thread, other threads:[~2006-06-06  5:36 UTC | newest]

Thread overview: 17+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-06-05 15:06 [gentoo-user] SSH authentication attempts - serious issue Leandro Melo de Sales
2006-06-05 15:27 ` Oliver Schmidt
2006-06-05 15:43   ` Richard Broersma Jr
2006-06-05 15:50   ` Willie Wong
2006-06-05 17:15   ` Leandro Melo de Sales
2006-06-05 17:47     ` Justin R Findlay
2006-06-05 22:21     ` Jeremy Olexa
2006-06-06  5:25       ` Leandro Melo de Sales
2006-06-05 17:56   ` Steven Susbauer
2006-06-05 15:30 ` Uwe Thiem
2006-06-05 16:09 ` Etaoin Shrdlu
2006-06-05 16:31 ` Joseph
2006-06-05 17:11   ` Leandro Melo de Sales
2006-06-05 17:12     ` Leandro Melo de Sales
2006-06-05 17:54       ` Petr Uzel
2006-06-05 20:48         ` Joseph
  -- strict thread matches above, loose matches on Subject: below --
2006-06-05 16:36 CR Little

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox