Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.misc > #12254 > unrolled thread

fedora 20 disabling ssh by default

Started by"Bill Cunningham" <nospam@nspam.invalid>
First post2014-10-09 19:23 -0400
Last post2014-10-30 07:34 +0000
Articles 20 on this page of 39 — 12 participants

Back to article view | Back to comp.os.linux.misc


Contents

  fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-09 19:23 -0400
    Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-09 23:35 +0000
      Re: fedora 20 disabling ssh by default Baho Utot <baho-utot@columbus.rr.com> - 2014-10-09 20:25 -0400
        Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-10 01:11 +0000
        Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:32 +0000
          Re: fedora 20 disabling ssh by default Baho Utot <baho-utot@columbus.rr.com> - 2014-10-10 17:59 -0400
      Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-09 23:13 -0400
        Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-10 08:50 +0000
          Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-10 09:10 +0000
            Re: fedora 20 disabling ssh by default The Natural Philosopher <tnp@invalid.invalid> - 2014-10-10 10:16 +0100
              Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 20:05 -0400
                Re: fedora 20 disabling ssh by default The Natural Philosopher <tnp@invalid.invalid> - 2014-10-11 07:47 +0100
            Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-10 09:26 +0000
              Re: fedora 20 disabling ssh by default The Natural Philosopher <tnp@invalid.invalid> - 2014-10-10 11:00 +0100
              Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-10 10:14 +0000
                Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-10 10:29 +0000
              Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 16:27 -0400
            Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:41 +0000
              Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 20:03 -0400
                Re: fedora 20 disabling ssh by default John Hasler <jhasler@newsguy.com> - 2014-10-10 20:28 -0500
                Re: fedora 20 disabling ssh by default Robert Riches <spamtrap42@jacob21819.net> - 2014-10-11 02:52 +0000
                  Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-11 17:03 +0000
                    Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-11 14:38 -0400
                      Re: fedora 20 disabling ssh by default Wayne <nospam@all.invalid> - 2014-10-11 18:05 -0400
                        Re: fedora 20 disabling ssh by default Richard Kettlewell <rjk@greenend.org.uk> - 2014-10-11 23:18 +0100
                        Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-11 23:43 +0000
                      Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-11 22:34 +0000
                        Re: fedora 20 disabling ssh by default Wayne <nospam@all.invalid> - 2014-10-11 19:13 -0400
                          Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-12 00:30 +0000
                            Re: fedora 20 disabling ssh by default Wayne <nospam@all.invalid> - 2014-10-11 21:27 -0400
                              Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-12 02:14 +0000
                Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-11 03:59 +0000
        Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:34 +0000
    Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:31 +0000
    Re: fedora 20 disabling ssh by default Andreas Kohlbach <oct14.5.ankman@spamgourmet.com> - 2014-10-10 16:06 -0400
      Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 20:00 -0400
        Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-11 17:02 +0000
        Re: fedora 20 disabling ssh by default Andreas Kohlbach <oct14.5.ankman@spamgourmet.com> - 2014-10-11 16:35 -0400
    Re: fedora 20 disabling ssh by default HakTar <FiteWinTel@gmail.com> - 2014-10-30 07:34 +0000

Page 1 of 2  [1] 2  Next page →


#12254 — fedora 20 disabling ssh by default

From"Bill Cunningham" <nospam@nspam.invalid>
Date2014-10-09 19:23 -0400
Subjectfedora 20 disabling ssh by default
Message-ID<m175d3$mtg$1@speranza.aioe.org>
    Hi,

I can't find in fedora like there seems to be in other distros a config file 
for ssh. There is the sshd that constrols the service. People are trying to 
hack me. I did use this to turn it off.

service sshd stop

Which in turn caused systemctl to deactivate ssh(d). Not can I turn this off 
by default?

Bill

[toc] | [next] | [standalone]


#12255

FromBit Twister <BitTwister@mouse-potato.com>
Date2014-10-09 23:35 +0000
Message-ID<slrnm3e6v1.g24.BitTwister@wb.home.test>
In reply to#12254
On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
>     Hi,
>
> I can't find in fedora like there seems to be in other distros a config file 
> for ssh.

It should not be hard to find, try
 locate ssh | grep conf | grep etc

> There is the sshd that constrols the service. People are trying to 
> hack me. I did use this to turn it off.
>
> service sshd stop
>
> Which in turn caused systemctl to deactivate ssh(d).

No it did not deactivate it, It did shut down the sshd service/daemon.
Next boot, sshd will be running again.

> Not can I turn this off by default?

Yes,  "systemctl disable sshd," disables sshd from being started during boot.

You can still do a systemctl start sshd when you need it to run then
systemctl stop sshd when done.

 

[toc] | [prev] | [next] | [standalone]


#12256

FromBaho Utot <baho-utot@columbus.rr.com>
Date2014-10-09 20:25 -0400
Message-ID<ejljgb-beb.ln1@raspberrypi.bildanet.com>
In reply to#12255
Bit Twister wrote:

> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
>>     Hi,
>>
>> I can't find in fedora like there seems to be in other distros a config
>> file for ssh.
> 
> It should not be hard to find, try
>  locate ssh | grep conf | grep etc
> 
>> There is the sshd that constrols the service. People are trying to
>> hack me. I did use this to turn it off.
>>
>> service sshd stop
>>
>> Which in turn caused systemctl to deactivate ssh(d).
> 
> No it did not deactivate it, It did shut down the sshd service/daemon.
> Next boot, sshd will be running again.
> 
>> Not can I turn this off by default?
> 
> Yes,  "systemctl disable sshd," disables sshd from being started during
> boot.
> 
> You can still do a systemctl start sshd when you need it to run then
> systemctl stop sshd when done.

Can I ssh in to the box to run the above commands? ;)

[toc] | [prev] | [next] | [standalone]


#12258

FromBit Twister <BitTwister@mouse-potato.com>
Date2014-10-10 01:11 +0000
Message-ID<slrnm3echf.uli.BitTwister@wb.home.test>
In reply to#12256
On Thu, 09 Oct 2014 20:25:32 -0400, Baho Utot wrote:

> Can I ssh in to the box to run the above commands? ;)

I do not see why not. I suggest doing it in this order though:

 systemctl disable sshd
 systemctl stop sshd

Keep in mind you will not get back into the box via ssh until a
 systemctl start sshd is issued on that box.

[toc] | [prev] | [next] | [standalone]


#12268

FromWilliam Unruh <unruh@invalid.ca>
Date2014-10-10 15:32 +0000
Message-ID<m18u6u$la4$2@dont-email.me>
In reply to#12256
On 2014-10-10, Baho Utot <baho-utot@columbus.rr.com> wrote:
> Bit Twister wrote:
>
>> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
>>>     Hi,
>>>
>>> I can't find in fedora like there seems to be in other distros a config
>>> file for ssh.
>> 
>> It should not be hard to find, try
>>  locate ssh | grep conf | grep etc
>> 
>>> There is the sshd that constrols the service. People are trying to
>>> hack me. I did use this to turn it off.
>>>
>>> service sshd stop
>>>
>>> Which in turn caused systemctl to deactivate ssh(d).
>> 
>> No it did not deactivate it, It did shut down the sshd service/daemon.
>> Next boot, sshd will be running again.
>> 
>>> Not can I turn this off by default?
>> 
>> Yes,  "systemctl disable sshd," disables sshd from being started during
>> boot.
>> 
>> You can still do a systemctl start sshd when you need it to run then
>> systemctl stop sshd when done.
>
> Can I ssh in to the box to run the above commands? ;)

Not if you have disabled ssh. 

[toc] | [prev] | [next] | [standalone]


#12277

FromBaho Utot <baho-utot@columbus.rr.com>
Date2014-10-10 17:59 -0400
Message-ID<hd1mgb-sjc.ln1@raspberrypi.bildanet.com>
In reply to#12268
William Unruh wrote:

> On 2014-10-10, Baho Utot <baho-utot@columbus.rr.com> wrote:
>> Bit Twister wrote:
>>
>>> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
>>>>     Hi,
>>>>
>>>> I can't find in fedora like there seems to be in other distros a config
>>>> file for ssh.
>>> 
>>> It should not be hard to find, try
>>>  locate ssh | grep conf | grep etc
>>> 
>>>> There is the sshd that constrols the service. People are trying to
>>>> hack me. I did use this to turn it off.
>>>>
>>>> service sshd stop
>>>>
>>>> Which in turn caused systemctl to deactivate ssh(d).
>>> 
>>> No it did not deactivate it, It did shut down the sshd service/daemon.
>>> Next boot, sshd will be running again.
>>> 
>>>> Not can I turn this off by default?
>>> 
>>> Yes,  "systemctl disable sshd," disables sshd from being started during
>>> boot.
>>> 
>>> You can still do a systemctl start sshd when you need it to run then
>>> systemctl stop sshd when done.
>>
>> Can I ssh in to the box to run the above commands? ;)
> 
> Not if you have disabled ssh.

Should work if I have not disabled sshd tho ;)

[toc] | [prev] | [next] | [standalone]


#12259

From"Bill Cunningham" <nospam@nspam.invalid>
Date2014-10-09 23:13 -0400
Message-ID<m17is4$f22$1@speranza.aioe.org>
In reply to#12255
"Bit Twister" <BitTwister@mouse-potato.com> wrote in message 
news:slrnm3e6v1.g24.BitTwister@wb.home.test...
> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
>>     Hi,
>>
>> I can't find in fedora like there seems to be in other distros a config 
>> file
>> for ssh.
>
> It should not be hard to find, try
> locate ssh | grep conf | grep etc
>
>> There is the sshd that constrols the service. People are trying to
>> hack me. I did use this to turn it off.
>>
>> service sshd stop
>>
>> Which in turn caused systemctl to deactivate ssh(d).
>
> No it did not deactivate it, It did shut down the sshd service/daemon.
> Next boot, sshd will be running again.
>
>> Not can I turn this off by default?
>
> Yes,  "systemctl disable sshd," disables sshd from being started during 
> boot.
>
> You can still do a systemctl start sshd when you need it to run then
> systemctl stop sshd when done.

    I logged on the other day and the shell told me that there was over 400 
attempts by a certain IP address to connect. It must've been while I was 
using the machine and didn't notice it.

Bill

[toc] | [prev] | [next] | [standalone]


#12260

FromRich <rich@example.invalid>
Date2014-10-10 08:50 +0000
Message-ID<m186ko$8na$1@dont-email.me>
In reply to#12259
Bill Cunningham <nospam@nspam.invalid> wrote:

> "Bit Twister" <BitTwister@mouse-potato.com> wrote in message 
> news:slrnm3e6v1.g24.BitTwister@wb.home.test...
> > On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
> >>     Hi,
> >>
> >> I can't find in fedora like there seems to be in other distros a
> >> config file for ssh.
> >
> > It should not be hard to find, try
> > locate ssh | grep conf | grep etc
> >
> >> There is the sshd that constrols the service. People are trying to
> >> hack me. I did use this to turn it off.
> >>
> >> service sshd stop
> >>
> >> Which in turn caused systemctl to deactivate ssh(d).
> >
> > No it did not deactivate it, It did shut down the sshd
> > service/daemon. Next boot, sshd will be running again.
> >
> >> Not can I turn this off by default?
> >
> > Yes,  "systemctl disable sshd," disables sshd from being started
> > during boot.
> >
> > You can still do a systemctl start sshd when you need it to run
> > then systemctl stop sshd when done.

>     I logged on the other day and the shell told me that there was
> over 400 attempts by a certain IP address to connect. It must've been
> while I was using the machine and didn't notice it.

> Bill

That is most likely a brute force password attempt.  If you shutdown
ssh, you'll block the attempts, but also prevent yourself from logging
in via ssh.  So if you log in via ssh, you'll end up shutting yourself
out as well.

However, if your password is properly random, you have little to worry
about other than extra entries in your log files.

But if you want to block the attempts, you could install sshfaker
(http://www.pkts.ca/ssh-faker.shtml) or fail2ban
(http://www.fail2ban.org/wiki/index.php/Main_Page) and block the brute
force password attempt, while leaving ssh open for yourself to use.

[toc] | [prev] | [next] | [standalone]


#12261

FromBit Twister <BitTwister@mouse-potato.com>
Date2014-10-10 09:10 +0000
Message-ID<slrnm3f8kc.k2m.BitTwister@wb.home.test>
In reply to#12260
On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote:
>
> That is most likely a brute force password attempt.  If you shutdown
> ssh, you'll block the attempts, but also prevent yourself from logging
> in via ssh.  So if you log in via ssh, you'll end up shutting yourself
> out as well.

Just tell your firewall what ip addresses are allowed to connect to sshd. 
Tell sshd that root is not allowed to use a password login.
Tell sshd to listen on a different port.


> However, if your password is properly random, you have little to worry
> about other than extra entries in your log files.

Random passwords are easier to crack. Use a funky phrase like
my dog eats concrete. 
Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.

[toc] | [prev] | [next] | [standalone]


#12262

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2014-10-10 10:16 +0100
Message-ID<m18851$feb$1@news.albasani.net>
In reply to#12261
On 10/10/14 10:10, Bit Twister wrote:
> Random passwords are easier to crack.


Blimey.

Has anyone told GCHQ?


-- 
Everything you read in newspapers is absolutely true, except for the 
rare story of which you happen to have first-hand knowledge. – Erwin Knoll

[toc] | [prev] | [next] | [standalone]


#12281

From"Bill Cunningham" <nospam@nspam.invalid>
Date2014-10-10 20:05 -0400
Message-ID<m19s7c$176$1@speranza.aioe.org>
In reply to#12262
"The Natural Philosopher" <tnp@invalid.invalid> wrote in message 
news:m18851$feb$1@news.albasani.net...
> On 10/10/14 10:10, Bit Twister wrote:
>> Random passwords are easier to crack.
>
>
> Blimey.
>
> Has anyone told GCHQ?

    I'm lost on that one. Is that anything like LGBT ? ;)

Bill

[toc] | [prev] | [next] | [standalone]


#12285

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2014-10-11 07:47 +0100
Message-ID<m1ajpg$smd$2@news.albasani.net>
In reply to#12281
On 11/10/14 01:05, Bill Cunningham wrote:
> "The Natural Philosopher" <tnp@invalid.invalid> wrote in message
> news:m18851$feb$1@news.albasani.net...
>> On 10/10/14 10:10, Bit Twister wrote:
>>> Random passwords are easier to crack.
>>
>>
>> Blimey.
>>
>> Has anyone told GCHQ?
>
>      I'm lost on that one. Is that anything like LGBT ? ;)
>
> Bill
>
>
http://lmgtfy.com/?q=GCHQ


-- 
Everything you read in newspapers is absolutely true, except for the 
rare story of which you happen to have first-hand knowledge. – Erwin Knoll

[toc] | [prev] | [next] | [standalone]


#12263

FromRich <rich@example.invalid>
Date2014-10-10 09:26 +0000
Message-ID<m188ng$ee8$1@dont-email.me>
In reply to#12261
Bit Twister <BitTwister@mouse-potato.com> wrote:
> On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote:
> > However, if your password is properly random, you have little to
> > worry about other than extra entries in your log files.

> Random passwords are easier to crack.

No.  "properly random" means the password should look like this:

=~dWx9C9pJq04lGMKh~C

or this

V064pb+e6)Sf/K?20/hf

Which are not "easier to crack" but quite the opposite, significantly
harder (note - the above two are not in use, and as they are randomly
generated, never will be).

> Use a funky phrase like
> my dog eats concrete. 
> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.

Not at all safe.  The automatic crackers already know how to generate
phrases with numbers and those characters sprinkled in, so that is
actually easier to crack than a "properly random" password.

[toc] | [prev] | [next] | [standalone]


#12264

FromThe Natural Philosopher <tnp@invalid.invalid>
Date2014-10-10 11:00 +0100
Message-ID<m18ann$ksr$1@news.albasani.net>
In reply to#12263
On 10/10/14 10:26, Rich wrote:
> Bit Twister <BitTwister@mouse-potato.com> wrote:
>> On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote:
>>> However, if your password is properly random, you have little to
>>> worry about other than extra entries in your log files.
>
>> Random passwords are easier to crack.
>
> No.  "properly random" means the password should look like this:
>
> =~dWx9C9pJq04lGMKh~C
>
> or this
>
> V064pb+e6)Sf/K?20/hf
>
> Which are not "easier to crack" but quite the opposite, significantly
> harder (note - the above two are not in use, and as they are randomly
> generated, never will be).
>
>> Use a funky phrase like
>> my dog eats concrete.
>> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.
>
> Not at all safe.  The automatic crackers already know how to generate
> phrases with numbers and those characters sprinkled in, so that is
> actually easier to crack than a "properly random" password.
>

Try every word in the dictionary, then in combinations separated by 
'unusual' characters, then with certain letters replaced by numbers.


That's the starting point for a dictionary attack.



-- 
Everything you read in newspapers is absolutely true, except for the 
rare story of which you happen to have first-hand knowledge. – Erwin Knoll

[toc] | [prev] | [next] | [standalone]


#12265

FromBit Twister <BitTwister@mouse-potato.com>
Date2014-10-10 10:14 +0000
Message-ID<slrnm3fcc3.k2m.BitTwister@wb.home.test>
In reply to#12263
On Fri, 10 Oct 2014 09:26:08 +0000 (UTC), Rich wrote:
> Bit Twister <BitTwister@mouse-potato.com> wrote:

>> Random passwords are easier to crack.
>
> No.  "properly random" means the password should look like this:
>
> =~dWx9C9pJq04lGMKh~C
>
> or this
>
> V064pb+e6)Sf/K?20/hf

Yes I understood the word random.

> Which are not "easier to crack" but quite the opposite, significantly
> harder (note - the above two are not in use, and as they are randomly
> generated, never will be).

Frap, I can not find the article showing random password crack time was way
less than a funky word string.

Hardcore crackers are using several video card gpus to crack passwords.

>> Use a funky phrase like
>> my dog eats concrete. 
>> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.
>
> Not at all safe.  The automatic crackers already know how to generate
> phrases with numbers and those characters sprinkled in, so that is
> actually easier to crack than a "properly random" password.

I completely agree with you with a single password.

Since I can not find the article, we are at the end of this discussion.

Now assuming Fedora 20 has a 3 second delay between each failed
attempt, it is going to take quite awhile to finally hit on any
reasonable strong phrase as the password.

Just don't use any quote or current buzz words.

[toc] | [prev] | [next] | [standalone]


#12266

FromRich <rich@example.invalid>
Date2014-10-10 10:29 +0000
Message-ID<m18ce0$r77$1@dont-email.me>
In reply to#12265
Bit Twister <BitTwister@mouse-potato.com> wrote:
> On Fri, 10 Oct 2014 09:26:08 +0000 (UTC), Rich wrote:
> > Bit Twister <BitTwister@mouse-potato.com> wrote:

> >> Random passwords are easier to crack.
> >
> > No.  "properly random" means the password should look like this:
> >
> > =~dWx9C9pJq04lGMKh~C
> >
> > or this
> >
> > V064pb+e6)Sf/K?20/hf

> Yes I understood the word random.

> > Which are not "easier to crack" but quite the opposite, significantly
> > harder (note - the above two are not in use, and as they are randomly
> > generated, never will be).

> Frap, I can not find the article showing random password crack time was way
> less than a funky word string.

Here is one: How much time is needed to crack a password by
             brute-force?

At the bottom of their "time table": 

length: 10, complexity: a-zA-Z0-9 + symbols ==> 91800 years

> Hardcore crackers are using several video card gpus to crack passwords.

Which simply means you need to increase the length of your passwords to
compensate (that, and the services storing them need to use a proper
work adjustable password storage function like bcrypt or scrypt).

For whatever speed the gpu crackers achieve, there is a password length
that exceeds their capabilities.  Which is why arbitrary length limits
on so many password protected services are actually more dangerous than
good.  You are prevented from keeping pace with the gpu crackers.

[toc] | [prev] | [next] | [standalone]


#12272

From"Bill Cunningham" <nospam@nspam.invalid>
Date2014-10-10 16:27 -0400
Message-ID<m19ffh$58f$1@speranza.aioe.org>
In reply to#12263
"Rich" <rich@example.invalid> wrote in message 
news:m188ng$ee8$1@dont-email.me...
> Bit Twister <BitTwister@mouse-potato.com> wrote:

> Which are not "easier to crack" but quite the opposite, significantly
> harder (note - the above two are not in use, and as they are randomly
> generated, never will be).

    I that depends on entropy and other things.

Bill


[toc] | [prev] | [next] | [standalone]


#12270

FromWilliam Unruh <unruh@invalid.ca>
Date2014-10-10 15:41 +0000
Message-ID<m18un5$la4$4@dont-email.me>
In reply to#12261
On 2014-10-10, Bit Twister <BitTwister@mouse-potato.com> wrote:
> On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote:
>>
>> That is most likely a brute force password attempt.  If you shutdown
>> ssh, you'll block the attempts, but also prevent yourself from logging
>> in via ssh.  So if you log in via ssh, you'll end up shutting yourself
>> out as well.
>
> Just tell your firewall what ip addresses are allowed to connect to sshd. 
> Tell sshd that root is not allowed to use a password login.
> Tell sshd to listen on a different port.
>
>
>> However, if your password is properly random, you have little to worry
>> about other than extra entries in your log files.
>
> Random passwords are easier to crack. Use a funky phrase like
> my dog eats concrete. 
> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.

He did say "properly random". I am sure by properly he did not mean 4
random characters. A long enough password with random characters is
certainly better than your example which really is not terribly random. 

[toc] | [prev] | [next] | [standalone]


#12280

From"Bill Cunningham" <nospam@nspam.invalid>
Date2014-10-10 20:03 -0400
Message-ID<m19s3t$148$1@speranza.aioe.org>
In reply to#12270
"William Unruh" <unruh@invalid.ca> wrote in message 
news:m18un5$la4$4@dont-email.me...
> On 2014-10-10, Bit Twister <BitTwister@mouse-potato.com> wrote:
>> On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote:
>>>
>>> That is most likely a brute force password attempt.  If you shutdown
>>> ssh, you'll block the attempts, but also prevent yourself from logging
>>> in via ssh.  So if you log in via ssh, you'll end up shutting yourself
>>> out as well.
>>
>> Just tell your firewall what ip addresses are allowed to connect to sshd.
>> Tell sshd that root is not allowed to use a password login.
>> Tell sshd to listen on a different port.
>>
>>
>>> However, if your password is properly random, you have little to worry
>>> about other than extra entries in your log files.
>>
>> Random passwords are easier to crack. Use a funky phrase like
>> my dog eats concrete.
>> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.
>
> He did say "properly random". I am sure by properly he did not mean 4
> random characters. A long enough password with random characters is
> certainly better than your example which really is not terribly random.

    Something generated by uuid would I think be pretty good. Or better yet 
if you could direct something from dev/urandom as text; but I don't know if 
you could do that.

Bill

[toc] | [prev] | [next] | [standalone]


#12282

FromJohn Hasler <jhasler@newsguy.com>
Date2014-10-10 20:28 -0500
Message-ID<8761frbdii.fsf@thumper.dhh.gt.org>
In reply to#12280
Bill Cunningham writes:
> Something generated by uuid would I think be pretty good. Or better
> yet if you could direct something from dev/urandom as text; but I
> don't know if you could do that.

Of course you could, but it's simpler to use a program such as pwgen.
-- 
John Hasler 
jhasler@newsguy.com
Dancing Horse Hill
Elmwood, WI USA

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | comp.os.linux.misc


csiph-web