|
|
||||||
|
||||||
| Index Link To US Private Messages Archive FAQ RSS | ||||||
| IT Discussion Forum Having IT issues? Got IT questions? Who doesn't? If you can't get your Apache to work with your MySQL or your php is choking on your ODBC... Let's see if we can help you come up with some ideas. |
Share Thread: & Tags
|
||||
|
![]() |
|
|
LinkBack | Thread Tools | Display Modes |
|
|||
|
Hey all,
We keep our boxes pretty tightly wrapped.. but in the last week or two, we have been seeing an increase in attempted logins via ssh. Anyone else seeing this? Has some 'new' exploit been published.. or are old ones just making a new resurgence. (hmm..school back in session.. computer labs are now open..)
__________________
Hardcore Programming Solutions and Coffee Drinker |
|
|||
|
We've had an enormous increase in zombie attacks from compromised machines on large ISP's in EU countries. There are tons of them all over Europe and we just saw an increse in IP's originating in Japan (up over 50% this week). It comes and goes in waves.
We've already blocked about every IP block in China and Korea to reduce dictionary attacks on two of our mail servers - customer has one of those dreaded domains that seems to get targeted frequently. Thankfully, he only does business in North America, so this was a practical thing to do. There is a comprehensive list of those IP addresses available at: http://www.okean.com/thegoods.html which is updated very daily. When used with APF or some other policy-based firewall it is almost 100% effective. Funny, but the zombies seem pretty particular - we have 5 production boxes and only 3 get the major traffic from them. Two rarely get probed. Our firewalls are now configured to let one login attempt from a non-white listed IP - if you blow it, you're out first try. This has helped, but we don't have a situation where there are any SSH users other than a small handful of admins, so the policy is effective. I'm sure the traffic from college networks will increase over the next few weeks with all those new computers coming up at once.... Unpatched, underprotected and noobs.....
__________________
:not_the_usual1 [you decide] ________________ All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store. |
|
|||
|
Check out this link for an eye-opener:
http://www.fcw.com/article90262-08-22-05-Print talks about attacks from overseas.
__________________
:not_the_usual1 [you decide] ________________ All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store. |
|
|||
|
There are some known exploits for F*Page enabled Websites that can be triggered via a form's content and subsequent posting.
Problemo is that the trolls that are doing it aren't always checking to see if the site is F*Page enabled before trying the exploit. As an example, the exploits are useless on a *nix server running the current extensions for the simple reason the exploit is to try to gain control of an unpatched M$ O/S server. Many of the zombies out there aren't being controlled by a very bright crew. These things seem to last for a week or two and then fade away - all we can figure is that the trolls lost their lease on the zombie machnes they were using.....
__________________
:not_the_usual1 [you decide] ________________ All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store. |
|
|||
|
Yes, that's a good idea, Easywebdev
We've also moved ssh to another port on most of our boxes. Helps alot Web Hosting | Webmaster Help |
|
|||
|
How do you spot an SSH attack attempt?
Which log should I look at please? I've recently got a dedicated *nix server and could use a pointer for this topic. Thanks |
|
|||
|
Steve - Do you have a firewall installed? What flavor of *nix is it? Is there any control panel (like plesk or c-panel)?
I'll try to help you get it hardened from this type of stuff.
__________________
:not_the_usual1 [you decide] ________________ All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store. |
|
|||
|
Hi, thanks.
It's Fedora Core and Plesk. |
|
|||
|
First - turn everything like PHPBB and Nuke off until you know they are patched correctly. They are really wek spots if not done right.
OK - start reading here: http://members.lycos.co.uk/bubudiu/fc3-harden/ http://www.eth0.us/ The first link refers to hardening fedora in particular and is written by a RedHat staffer. The second link takes on the whole system. Pay particular attention to the firewall section - they recommend using APF - which really is the best way to go. Also, when you get the latest version of APF, they've integrated a few new tools (like anti-DOS and a brute force detection system). Let me know when you've plowed through this stuff and I'll help anywhere I can.
__________________
:not_the_usual1 [you decide] ________________ All in my opinion, which, when combined carefully with a $1 bill, gets you a cup of coffee at the corner store. |
|
|||
|
Thanks, will get reading...
|
![]() |
|
| Thread Tools | |
| Display Modes | |
|
|
|
WebProWorld |
Advertise |
Contact Us |
About |
Forum Rules |
MVP's |
Archive |
Newsletter Archive |
Top |
WebProNews
WebProWorld is an iEntry, Inc. ® site - © 2009 All Rights Reserved Privacy Policy and Legal iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509 |