Re: ssh brute force attacks
Peter Espen <[email protected]> Sat, 29 Jan 2011 10:10:06 -0700
| Newsgroups | gmane.org.user-groups.nmlug |
|---|---|
| Message-ID | <[email protected]> |
In addition, I wrote a script that's in crontab and it examines auth.log and automatically blocks the offending originating IP address via iptables. Peter -- On Jan 28, 2011, at 11:42 PM, J. Marsden DeLapp wrote: > On Friday 28 January 2011 3:18:37 pm Ed Heron <Ed-MBvgLuVkLo/[email protected]> wrote: >> What is the deal with the SSH brute force attacks? I wasn't paying >> attention until recently, but some of my new CentOS machines are giving >> me reports of all the failed login attempts. >> >> Most attackers (several dozen per day) try once every 15 to 20 >> minutes. I assume to avoid automatically being banned. Some were >> throwing thousands of attempts at me from a single IP address. It might >> have been happening on my old servers, but I'm afraid to look. >> >> I didn't have any automatic banning software installed before, but I >> do now. >> >> However, it makes me think about SSH. It is a secure protocol but a >> bad password could open my system up to exploitation. This isn't a SSH >> fault but a lack of confidence in my users. And we don't even use SSH >> from outside the private network that often (just me for maintenance). > > Here are a few things I do to increase SSH security. > > Create a sshuser group and require anyone who needs ssh access to be in that group. > > vim /etc/ssh/sshd_config > #change to not allow root login > PermitRootLogin no > #added sshuser group and > #Added to restrict ssh login to people in the sshuser group > AllowGroups sshuser > > Anyone who is a ssh user should have a unique userID. Don't use common names > like bob, chuck, fred, admin, staff, etc. Things like bobjones, chucksmith are better choices. > > Another cute trick to slow them down is to rate limit connections. > > #These two commands will rate limit connection attempts on ssh > iptables -A INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set > iptables -A INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 -j DROP > > But that does not work against the distributed attacks coming from a slew of different > ip addresses. And it sets you up for a potential denial of service attack. If you do the > rate limiting thing, make sure you tell your users if they have three failed login attempts, > they need to wait for at least 60 seconds before trying again. > > Mars > > -- > ============================================================= > J. Marsden DeLapp, PE > President > DeLapp & Associates, Inc. dba DeLapp Engineering. > Providing lighting and power planning, design and analysis services > for commercial, industrial and large residential facilities. > 1190 Harrison Road Ste 3a > Santa Fe NM 87507 > (505) 983-5557 > http://DeLapp.com > ============================================================= > _______________________________________________ > NMLUG mailing list > [email protected] > http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug _______________________________________________ NMLUG mailing list [email protected] http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug