Computer Geeks

Computer Geeks

Geek Shop

Geek News

Geek Stuff

Science Geek

Computer Gaming

Linux Chat

Building Websites

Computer Forums

Computer Help Forum

Computer Hardware Forum

Computer Software Programs


Go Back   Computer Forums > Building Websites
FAQ Community Calendar Today's Posts Search

Building Websites This section covers all aspects of publishing, developing and maintaining websites. Topics include: website design, graphic design, website programming, web hosting, website marketing (SEO, link exchange, publicity, advertising), monetization & etc.

Computer Geeks
» Active Discussions
Computer Geeks
No Threads to Display.
» Other Websites
- Software Publishing

- Server Hardening
Reply
 
Thread Tools Display Modes
  #1  
Old 03-01-2006, 06:53 PM
Emma Emma is offline
Junior Member
GB Newbie
 
Join Date: Mar 2006
Posts: 3
Default Preventing SSH Dictionary Attacks With DenyHosts

Preventing SSH Dictionary Attacks With DenyHosts

"DenyHosts is a script intended to be run by Linux system administrators to help thwart ssh server attacks.

If you've ever looked at your ssh log (/var/log/secure on Redhat, /var/log/auth.log on Mandrake, etc...) you may be alarmed to see how many hackers attempted to gain access to your server. Hopefully, none of them were successful (but then again, how would you know?). Wouldn't it be better to automatically prevent that attacker from continuing to gain entry into your system?

DenyHosts attempts to address the above... "

I found this tutorial very helpful and I thought I would share it with you guys, so you can learn how to protect your servers better. Of course, most of you are probably old hands at this, but still it is good to start with the basics.
Reply With Quote
  #2  
Old 03-01-2006, 08:29 PM
Jason's Avatar
Jason Jason is offline
VIP Member
GB Beginner
 
Join Date: Feb 2006
Posts: 35
Send a message via AIM to Jason Send a message via Yahoo to Jason
Default

Thank you for sharing with the community!
__________________
Unlimited Net
Reply With Quote
  #3  
Old 03-07-2006, 06:29 PM
James72 James72 is offline
Junior Member
GB Beginner
 
Join Date: Feb 2006
Posts: 29
Default

How well does this prevent attacks?
I will assume it is not bullet proof.

Is there anything else we can do to take steps to try and stop dictionary attacks?
________
e cigarette

Last edited by James72; 01-21-2011 at 08:34 PM.
Reply With Quote
  #4  
Old 03-07-2006, 08:43 PM
Soulwatcher's Avatar
Soulwatcher Soulwatcher is offline
Senior Member
GB GEEK
 
Join Date: Feb 2006
Posts: 309
Send a message via MSN to Soulwatcher
Default

Quote:
Originally Posted by James72
How well does this prevent attacks?
I will assume it is not bullet proof.

Is there anything else we can do to take steps to try and stop dictionary attacks?
You could install APF and BFD, and after so many attempts. It blocks the IP right at the firewall. For more information have a look at http://www.rfxnetworks.com/apf.php . Their website seems to be down at the moment. But It should be back up anytime.
Reply With Quote
  #5  
Old 03-08-2006, 11:45 AM
Rogue Rogue is offline
Junior Member
GB Beginner
 
Join Date: Mar 2006
Posts: 25
Default

Thank you VERY much for sharing this with me! I'm a beginner in the whole Linux server industry, and this is some great information.

Also - SoulWatcher - thanks very much for the link you have also provided.
__________________
Img-Upload - Free Image Hosting
Reply With Quote
  #6  
Old 03-12-2006, 03:42 AM
Julian Julian is offline
Junior Member
GB Beginner
 
Join Date: Mar 2006
Posts: 25
Send a message via AIM to Julian
Default

I'll have to forward this to my friend, for his web hosting company. I am pretty sure he has this already though.
Reply With Quote
  #7  
Old 04-20-2006, 07:10 PM
Heroin Heroin is offline
Junior Member
GB Beginner
 
Join Date: Apr 2006
Posts: 21
Default

i just closed port 22 on my router so only internal machines can SSH eachother
Reply With Quote
  #8  
Old 04-21-2006, 11:24 AM
LucnetSolutions's Avatar
LucnetSolutions LucnetSolutions is offline
Member
GB Beginner
 
Join Date: Mar 2006
Posts: 49
Send a message via AIM to LucnetSolutions Send a message via MSN to LucnetSolutions Send a message via Yahoo to LucnetSolutions
Default

One thing we do to add some more security for SSH is we don't use the shared IP as the listen IP for SSH and we don't use the standard port 22. SSH is disabled by default and can be turned on for 24 hours max at a time.

Then we also have it set where a email is sent with IP and ISP information of the person that just logged in.
__________________
Lucnet Solutions - World Wide Hosting Solutions
Reply With Quote
  #9  
Old 05-03-2006, 02:56 AM
rmwebs rmwebs is offline
Member
GB Beginner
 
Join Date: May 2006
Posts: 30
Default

Quote:
Originally Posted by LucnetSolutions
One thing we do to add some more security for SSH is we don't use the shared IP as the listen IP for SSH and we don't use the standard port 22. SSH is disabled by default and can be turned on for 24 hours max at a time.

Then we also have it set where a email is sent with IP and ISP information of the person that just logged in.
Good idea IMHO.
__________________
Own A Forum? - WhichBB
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Powered by vBadvanced CMPS v3.2.3

All times are GMT -5. The time now is 04:37 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
HTML Help provided by HTML Help Central.