Go Back   openSUSE Forums > Archives > SF Archives > ARCHIVES - Network/Internet
Forums FAQ Members List Search Today's Posts Mark Forums Read


ARCHIVES - Network/Internet Questions regarding network or Internet configuration and use in SUSE Linux

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 15-May-2008, 07:49
ingocnito9
Guest
 
Posts: n/a
Default

http://arstechnica.com/news.ars/post/20080...tacks-rise.html

While the title is sort of alarmist, it raises some interesting issues.

Is there a way to change the user "root" to something else? I think that would cut down on the effectiveness of brute force attacks on ssh by a fair margin. Unless one changed it to "Administrator" or something silly like that.

  #2 (permalink)  
Old 15-May-2008, 08:22
lattup
Guest
 
Posts: n/a
Default

As your linked article says:

If you've got an SSH server that you want to secure from brute-force attack, Owens and Matthews recommend:

· all passwords should be strong, usernames should be non-obvious

· SSH logins for the root account should be disabled

· run the SSH server on a non-standard high port ("security through obscurity" tactic)

· use software capable of parsing log files and noting multiple failed login attempts

These steps, taken in aggregate, should be sufficient to protect an SSH server, even if the number of attacks continues to rise.
 

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




 

Search Engine Friendly URLs by vBSEO 3.3.0 RC2