Go Back   Defender Hosting Forums > PowerVPS Virtual Private Servers > Linux VPS - Security and Tuning

Linux VPS - Security and Tuning Security and Tuning Discussion for Linux Virtual Private Servers based on Virtuozzo by SWsoft

Reply
 
Thread Tools Display Modes

  #1  
Old 10-04-2005, 02:53 PM
StingRay StingRay is offline
Senior Member
 
Join Date: Jul 2005
Posts: 155
StingRay is on a distinguished road
Default Port 22 Not being attacked.

I currently get about 5 Brute force attacks a day and find that the attacks never seem to target port 22 (default SSH port).

Is that odd? Seems to me that port 22 is more secure since no one ever trys it lol.
Reply With Quote

  #2  
Old 10-04-2005, 03:07 PM
elix elix is offline
Senior Member
 
Join Date: Jun 2005
Posts: 787
elix is on a distinguished road
Default

Some script kiddies don't even know what SSH is LOL
__________________
Got clue?
Reply With Quote

  #3  
Old 10-04-2005, 05:35 PM
capnqwest
Guest
 
Posts: n/a
Default

My attacks were always on port 22. They stopped once I changed the SSH port to something above 1024.
Reply With Quote

  #4  
Old 10-04-2005, 07:26 PM
vps-vince's Avatar
vps-vince vps-vince is offline
Senior Member
 
Join Date: Jun 2005
Location: London UK
Posts: 455
vps-vince is on a distinguished road
Default

Beginner question:
Where do you look to see and identify these attacks?


Cheers
Reply With Quote

  #5  
Old 10-04-2005, 08:05 PM
guapo guapo is offline
Junior Member
 
Join Date: Sep 2005
Posts: 8
guapo is on a distinguished road
Default

would be at your email if its set up to send you e-mail or at logs files
/var/log
if you do have some brute force program installed like BDF

type at ssh if im not wrong.
tail -f /var/log/bdf
Reply With Quote

  #6  
Old 10-05-2005, 03:59 AM
Zaf Zaf is offline
Senior Member
 
Join Date: Aug 2005
Posts: 294
Zaf is on a distinguished road
Default

Quote:
Originally Posted by guapo
type at ssh if im not wrong.
tail -f /var/log/bdf
the path of the logs look fine, but the command should be
Code:
root@host [~]# tail -f /var/log/bfd_log
__________________
Zaf
Reply With Quote

  #7  
Old 10-05-2005, 11:27 AM
StingRay StingRay is offline
Senior Member
 
Join Date: Jul 2005
Posts: 155
StingRay is on a distinguished road
Default

vince,
BFD sends me an email everytime it adds an IP to the firewall. I currently have it running every 10 minutes (which I intend to get around to changing to daemon), and with it set to 10 min, I quite often get 100's of attempts.

I have yet to see an attempt being made on a port with less than 5 digits. ie 45123, or 32345, etc.

The majority of attacks do seem to target the "root" user though, so i've set out to disable root login.

They also target common names and words, so Ive decided from now on I will make user names created on the server that include a number and are not dictionary words.
Reply With Quote

  #8  
Old 10-05-2005, 03:49 PM
chief's Avatar
chief chief is offline
Senior Member
 
Join Date: Jul 2005
Location: Schenectady, NY
Posts: 118
chief is on a distinguished road
Send a message via AIM to chief
Default

Same here (strange port attempts), and there are some damn strange name attempts too.
Reply With Quote

  #9  
Old 10-05-2005, 06:55 PM
vps-vince's Avatar
vps-vince vps-vince is offline
Senior Member
 
Join Date: Jun 2005
Location: London UK
Posts: 455
vps-vince is on a distinguished road
Default

Tried [~]# tail -f /var/log/bfd_log but it just hangs there doing nothing

I used sftp to download bfd_log.1 bfd_log.2 and so on, and they are empty, zero bytes.

Does that mean all is fine?

Thanks
Reply With Quote

  #10  
Old 10-05-2005, 08:55 PM
StingRay StingRay is offline
Senior Member
 
Join Date: Jul 2005
Posts: 155
StingRay is on a distinguished road
Default

Check /var/log/secure or secure.1 etc
Look for "Invalid user xxx from xxx.xxx.xxx.xxx"

If you have a bunch of those from the same IP, then BFD is not setup properly. (ie could be that it isn't working at all, or you have the allowed attempts too high)
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Work, school, library firewall restricting access ? Fred Linux VPS - HOWTOs and FAQs 1 05-22-2006 03:33 PM
Add smtp port (26) ? hagmund Linux VPS - General 2 05-18-2006 05:57 AM
[HOWTO] Port Forwarding/Tunneling MySQL thru SSH asterisk Linux VPS - HOWTOs and FAQs 2 03-12-2006 07:47 PM
Implelemnt simle port knocking zolee1 Linux VPS - Security and Tuning 5 10-17-2005 12:25 PM
ISP Port 25 Blocking Starchild The Lounge 3 08-30-2005 06:18 PM



All times are GMT -4. The time now is 12:45 AM.


vBulletin skin developed by: eXtremepixels
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Copyright Defender Technologies Group, LLC 2006