Go Back   openSUSE Forums > New User How To/FAQ (read only) > Unreviewed How To and FAQ
Forums FAQ Members List Search Today's Posts Mark Forums Read


Unreviewed How To and FAQ POST HERE: Tips and solutions for SUSE Linux from the community. (Please do not post questions)

Reply
Page 3 of 3 12 3
 
LinkBack Thread Tools Display Modes
  #21 (permalink)  
Old 06-Nov-2009, 02:17
tuxituk's Avatar
Explorer Penguin
 
Join Date: Oct 2008
Location: Manchester
Posts: 119
tuxituk hasn't been rated much yet
Default Re: Secure SSH - How To

Quote:
Originally Posted by cjcox View Post
On Tue, 2009-11-03 at 22:56 +0000, tuxituk wrote:[color=blue]

Sadly, the ssh client historically uses LOWERCASE -p whereas
the scp program uses UPPERCASE -P. Just an fyi...

.
Yep cheers for the feedback and the spot! Embarrassing typo.
__________________
Linux# makes_a_network_feel_good.sh

Linux and BSD solutions
Reply With Quote
  #22 (permalink)  
Old 07-Nov-2009, 15:34
cjcox's Avatar
Parent Penguin
 
Join Date: Jun 2008
Location: Frisco, TX
Posts: 776
cjcox hasn't been rated much yet
Default Re: Secure SSH - How To

Jim Henderson wrote:
> On Thu, 05 Nov 2009 22:05:41 +0000, cjcox wrote:
>
>> Hmmm... I'd say reducing your log sizes by literraly GIGABYTES daily is
>> a good thing... yes??

>
> GB? That would seem to indicate a bad logrotate policy to me.


Possibly. But probably NOT just a logrotate policy, but we could
take the logs during the day and somehow shuttle them
off somewhere... but when you're dealing with this much data,
it's a difficult problem no matter how you slice it up.

(which is why I love solutions that try to reduce the volume
of data to begin with).
Reply With Quote
  #23 (permalink)  
Old 08-Nov-2009, 12:44
Global Moderator
 
Join Date: Jul 2008
Location: Salt Lake City, Utah
Posts: 1,222
hendersj 's reputation will be famous soon enoughhendersj 's reputation will be famous soon enoughhendersj 's reputation will be famous soon enough
Default Re: Secure SSH - How To

On Sat, 07 Nov 2009 21:34:32 +0000, Chris Cox wrote:

> Jim Henderson wrote:
>> On Thu, 05 Nov 2009 22:05:41 +0000, cjcox wrote:
>>
>>> Hmmm... I'd say reducing your log sizes by literraly GIGABYTES daily
>>> is a good thing... yes??

>>
>> GB? That would seem to indicate a bad logrotate policy to me.

>
> Possibly. But probably NOT just a logrotate policy, but we could take
> the logs during the day and somehow shuttle them off somewhere... but
> when you're dealing with this much data, it's a difficult problem no
> matter how you slice it up.


Yeah, other things would contribute as well. I've got a kernel module
that gives me a useless message on an OES2 server - in that it doesn't
identify the module that's actually having the problem. I get about 3
messages a second in my logs as a result.

One of these days I'll track it down.

> (which is why I love solutions that try to reduce the volume of data to
> begin with).


You and me alike. :-)

Jim
--
Jim Henderson
openSUSE Forums Moderator
Reply With Quote
  #24 (permalink)  
Old 11-Nov-2009, 00:53
Student Penguin
 
Join Date: Apr 2009
Posts: 65
PVince81 hasn't been rated much yet
Default Re: Secure SSH - How To

At some time I also had SSH pointing outside on port 22, and saw a lot of brute force attacks on that port, with a lot of interesting user names.

To fix it I installed an SSH filter. Unfortunately I forgot the name of that tool and can't find it online.

The tool was a wrapper for SSH that will detect brute force attacks, then after a few attempts, it will add the attacker's IP to the firewall blocking rules (iptables) and remove it after a certain elapsed time.
Reply With Quote
  #25 (permalink)  
Old 12-Nov-2009, 16:24
Dexter1979's Avatar
Busy Penguin
 
Join Date: Jun 2008
Location: +52° 9' 13.68", -8° 37' 57.07"
Posts: 499
Dexter1979 's reputation will be famous soon enoughDexter1979 's reputation will be famous soon enoughDexter1979 's reputation will be famous soon enough
Default Re: Secure SSH - How To

Quote:
Originally Posted by PVince81 View Post
To fix it I installed an SSH filter. Unfortunately I forgot the name of that tool and can't find it online.
Is it in this article? Protecting SSH from brute force attacks

I'm no network manager but this is an interesting thread. So after some googling I found the above article. Makes for interesting reading.
__________________
Lord Flasheart: Always treat your plane like you treat your woman.
Lieutenant George: Take her home at the weekend to meet your mother?
Lord Flasheart: No, get inside her five times a day and take her to heaven and back!
Reply With Quote
  #26 (permalink)  
Old 12-Nov-2009, 19:44
Student Penguin
 
Join Date: Apr 2009
Posts: 65
PVince81 hasn't been rated much yet
Default Re: Secure SSH - How To

No, I used a different tool. It was back then in 2006.
But it looks like the tools from this article can achieve similar results. Good to know :-)
Reply With Quote
Reply
Page 3 of 3 12 3

Bookmarks


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On




 

Search Engine Friendly URLs by vBSEO 3.3.0 RC2