Re: ssh brute force attacks

Peter Espen <[email protected]> Sat, 29 Jan 2011 10:10:06 -0700
Newsgroups gmane.org.user-groups.nmlug
Message-ID <[email protected]>
In addition, I wrote a script that's in crontab and it examines auth.log and automatically blocks the offending originating IP address via iptables.

Peter
--

On Jan 28, 2011, at 11:42 PM, J. Marsden DeLapp wrote:

> On Friday 28 January 2011 3:18:37 pm Ed Heron <Ed-MBvgLuVkLo/[email protected]> wrote:
>>  What is the deal with the SSH brute force attacks?  I wasn't paying
>> attention until recently, but some of my new CentOS machines are giving
>> me reports of all the failed login attempts.
>> 
>>  Most attackers (several dozen per day) try once every 15 to 20
>> minutes.  I assume to avoid automatically being banned.  Some were
>> throwing thousands of attempts at me from a single IP address.  It might
>> have been happening on my old servers, but I'm afraid to look.
>> 
>>  I didn't have any automatic banning software installed before, but I
>> do now.
>> 
>>  However, it makes me think about SSH.  It is a secure protocol but a
>> bad password could open my system up to exploitation.  This isn't a SSH
>> fault but a lack of confidence in my users.  And we don't even use SSH
>> from outside the private network that often (just me for maintenance).
> 
> Here are a few things I do to increase SSH security.
> 
> Create a sshuser group and require anyone who needs ssh access to be in that group.
> 
> vim /etc/ssh/sshd_config
> #change to not allow root login
> PermitRootLogin no
> #added sshuser group and
> #Added to restrict ssh login to people in the sshuser group
> AllowGroups sshuser
> 
> Anyone who is a ssh user should have a unique userID. Don't use common names 
> like bob, chuck, fred, admin, staff, etc. Things like bobjones, chucksmith are better choices. 
> 
> Another cute trick to slow them down is to rate limit connections.
> 
> #These two commands will rate limit connection attempts on ssh
> iptables -A INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --set
> iptables -A INPUT -p tcp --dport 22 -i eth0 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 -j DROP
> 
> But that does not work against the distributed attacks coming from a slew of different 
> ip addresses. And it sets you up for a potential denial of service attack. If you do the
> rate limiting thing, make sure you tell your users if they have three failed login attempts, 
> they need to wait for at least 60 seconds before trying again.
> 
> Mars
> 
> -- 
> =============================================================
> J. Marsden DeLapp, PE
> President
> DeLapp & Associates, Inc. dba DeLapp Engineering.
> Providing lighting and power planning, design and analysis services
> for commercial, industrial and large residential facilities.
> 1190 Harrison Road Ste 3a
> Santa Fe NM 87507
> (505) 983-5557
> http://DeLapp.com
> =============================================================
> _______________________________________________
> NMLUG mailing list
> [email protected]
> http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug


_______________________________________________
NMLUG mailing list
[email protected]
http://lists.b9.com/cgi-bin/mailman/listinfo/nmlug