Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.misc > #12254 > unrolled thread
| Started by | "Bill Cunningham" <nospam@nspam.invalid> |
|---|---|
| First post | 2014-10-09 19:23 -0400 |
| Last post | 2014-10-30 07:34 +0000 |
| Articles | 20 on this page of 39 — 12 participants |
Back to article view | Back to comp.os.linux.misc
fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-09 19:23 -0400
Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-09 23:35 +0000
Re: fedora 20 disabling ssh by default Baho Utot <baho-utot@columbus.rr.com> - 2014-10-09 20:25 -0400
Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-10 01:11 +0000
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:32 +0000
Re: fedora 20 disabling ssh by default Baho Utot <baho-utot@columbus.rr.com> - 2014-10-10 17:59 -0400
Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-09 23:13 -0400
Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-10 08:50 +0000
Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-10 09:10 +0000
Re: fedora 20 disabling ssh by default The Natural Philosopher <tnp@invalid.invalid> - 2014-10-10 10:16 +0100
Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 20:05 -0400
Re: fedora 20 disabling ssh by default The Natural Philosopher <tnp@invalid.invalid> - 2014-10-11 07:47 +0100
Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-10 09:26 +0000
Re: fedora 20 disabling ssh by default The Natural Philosopher <tnp@invalid.invalid> - 2014-10-10 11:00 +0100
Re: fedora 20 disabling ssh by default Bit Twister <BitTwister@mouse-potato.com> - 2014-10-10 10:14 +0000
Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-10 10:29 +0000
Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 16:27 -0400
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:41 +0000
Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 20:03 -0400
Re: fedora 20 disabling ssh by default John Hasler <jhasler@newsguy.com> - 2014-10-10 20:28 -0500
Re: fedora 20 disabling ssh by default Robert Riches <spamtrap42@jacob21819.net> - 2014-10-11 02:52 +0000
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-11 17:03 +0000
Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-11 14:38 -0400
Re: fedora 20 disabling ssh by default Wayne <nospam@all.invalid> - 2014-10-11 18:05 -0400
Re: fedora 20 disabling ssh by default Richard Kettlewell <rjk@greenend.org.uk> - 2014-10-11 23:18 +0100
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-11 23:43 +0000
Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-11 22:34 +0000
Re: fedora 20 disabling ssh by default Wayne <nospam@all.invalid> - 2014-10-11 19:13 -0400
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-12 00:30 +0000
Re: fedora 20 disabling ssh by default Wayne <nospam@all.invalid> - 2014-10-11 21:27 -0400
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-12 02:14 +0000
Re: fedora 20 disabling ssh by default Rich <rich@example.invalid> - 2014-10-11 03:59 +0000
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:34 +0000
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-10 15:31 +0000
Re: fedora 20 disabling ssh by default Andreas Kohlbach <oct14.5.ankman@spamgourmet.com> - 2014-10-10 16:06 -0400
Re: fedora 20 disabling ssh by default "Bill Cunningham" <nospam@nspam.invalid> - 2014-10-10 20:00 -0400
Re: fedora 20 disabling ssh by default William Unruh <unruh@invalid.ca> - 2014-10-11 17:02 +0000
Re: fedora 20 disabling ssh by default Andreas Kohlbach <oct14.5.ankman@spamgourmet.com> - 2014-10-11 16:35 -0400
Re: fedora 20 disabling ssh by default HakTar <FiteWinTel@gmail.com> - 2014-10-30 07:34 +0000
Page 1 of 2 [1] 2 Next page →
| From | "Bill Cunningham" <nospam@nspam.invalid> |
|---|---|
| Date | 2014-10-09 19:23 -0400 |
| Subject | fedora 20 disabling ssh by default |
| Message-ID | <m175d3$mtg$1@speranza.aioe.org> |
Hi, I can't find in fedora like there seems to be in other distros a config file for ssh. There is the sshd that constrols the service. People are trying to hack me. I did use this to turn it off. service sshd stop Which in turn caused systemctl to deactivate ssh(d). Not can I turn this off by default? Bill
[toc] | [next] | [standalone]
| From | Bit Twister <BitTwister@mouse-potato.com> |
|---|---|
| Date | 2014-10-09 23:35 +0000 |
| Message-ID | <slrnm3e6v1.g24.BitTwister@wb.home.test> |
| In reply to | #12254 |
On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote: > Hi, > > I can't find in fedora like there seems to be in other distros a config file > for ssh. It should not be hard to find, try locate ssh | grep conf | grep etc > There is the sshd that constrols the service. People are trying to > hack me. I did use this to turn it off. > > service sshd stop > > Which in turn caused systemctl to deactivate ssh(d). No it did not deactivate it, It did shut down the sshd service/daemon. Next boot, sshd will be running again. > Not can I turn this off by default? Yes, "systemctl disable sshd," disables sshd from being started during boot. You can still do a systemctl start sshd when you need it to run then systemctl stop sshd when done.
[toc] | [prev] | [next] | [standalone]
| From | Baho Utot <baho-utot@columbus.rr.com> |
|---|---|
| Date | 2014-10-09 20:25 -0400 |
| Message-ID | <ejljgb-beb.ln1@raspberrypi.bildanet.com> |
| In reply to | #12255 |
Bit Twister wrote: > On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote: >> Hi, >> >> I can't find in fedora like there seems to be in other distros a config >> file for ssh. > > It should not be hard to find, try > locate ssh | grep conf | grep etc > >> There is the sshd that constrols the service. People are trying to >> hack me. I did use this to turn it off. >> >> service sshd stop >> >> Which in turn caused systemctl to deactivate ssh(d). > > No it did not deactivate it, It did shut down the sshd service/daemon. > Next boot, sshd will be running again. > >> Not can I turn this off by default? > > Yes, "systemctl disable sshd," disables sshd from being started during > boot. > > You can still do a systemctl start sshd when you need it to run then > systemctl stop sshd when done. Can I ssh in to the box to run the above commands? ;)
[toc] | [prev] | [next] | [standalone]
| From | Bit Twister <BitTwister@mouse-potato.com> |
|---|---|
| Date | 2014-10-10 01:11 +0000 |
| Message-ID | <slrnm3echf.uli.BitTwister@wb.home.test> |
| In reply to | #12256 |
On Thu, 09 Oct 2014 20:25:32 -0400, Baho Utot wrote: > Can I ssh in to the box to run the above commands? ;) I do not see why not. I suggest doing it in this order though: systemctl disable sshd systemctl stop sshd Keep in mind you will not get back into the box via ssh until a systemctl start sshd is issued on that box.
[toc] | [prev] | [next] | [standalone]
| From | William Unruh <unruh@invalid.ca> |
|---|---|
| Date | 2014-10-10 15:32 +0000 |
| Message-ID | <m18u6u$la4$2@dont-email.me> |
| In reply to | #12256 |
On 2014-10-10, Baho Utot <baho-utot@columbus.rr.com> wrote: > Bit Twister wrote: > >> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote: >>> Hi, >>> >>> I can't find in fedora like there seems to be in other distros a config >>> file for ssh. >> >> It should not be hard to find, try >> locate ssh | grep conf | grep etc >> >>> There is the sshd that constrols the service. People are trying to >>> hack me. I did use this to turn it off. >>> >>> service sshd stop >>> >>> Which in turn caused systemctl to deactivate ssh(d). >> >> No it did not deactivate it, It did shut down the sshd service/daemon. >> Next boot, sshd will be running again. >> >>> Not can I turn this off by default? >> >> Yes, "systemctl disable sshd," disables sshd from being started during >> boot. >> >> You can still do a systemctl start sshd when you need it to run then >> systemctl stop sshd when done. > > Can I ssh in to the box to run the above commands? ;) Not if you have disabled ssh.
[toc] | [prev] | [next] | [standalone]
| From | Baho Utot <baho-utot@columbus.rr.com> |
|---|---|
| Date | 2014-10-10 17:59 -0400 |
| Message-ID | <hd1mgb-sjc.ln1@raspberrypi.bildanet.com> |
| In reply to | #12268 |
William Unruh wrote: > On 2014-10-10, Baho Utot <baho-utot@columbus.rr.com> wrote: >> Bit Twister wrote: >> >>> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote: >>>> Hi, >>>> >>>> I can't find in fedora like there seems to be in other distros a config >>>> file for ssh. >>> >>> It should not be hard to find, try >>> locate ssh | grep conf | grep etc >>> >>>> There is the sshd that constrols the service. People are trying to >>>> hack me. I did use this to turn it off. >>>> >>>> service sshd stop >>>> >>>> Which in turn caused systemctl to deactivate ssh(d). >>> >>> No it did not deactivate it, It did shut down the sshd service/daemon. >>> Next boot, sshd will be running again. >>> >>>> Not can I turn this off by default? >>> >>> Yes, "systemctl disable sshd," disables sshd from being started during >>> boot. >>> >>> You can still do a systemctl start sshd when you need it to run then >>> systemctl stop sshd when done. >> >> Can I ssh in to the box to run the above commands? ;) > > Not if you have disabled ssh. Should work if I have not disabled sshd tho ;)
[toc] | [prev] | [next] | [standalone]
| From | "Bill Cunningham" <nospam@nspam.invalid> |
|---|---|
| Date | 2014-10-09 23:13 -0400 |
| Message-ID | <m17is4$f22$1@speranza.aioe.org> |
| In reply to | #12255 |
"Bit Twister" <BitTwister@mouse-potato.com> wrote in message
news:slrnm3e6v1.g24.BitTwister@wb.home.test...
> On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote:
>> Hi,
>>
>> I can't find in fedora like there seems to be in other distros a config
>> file
>> for ssh.
>
> It should not be hard to find, try
> locate ssh | grep conf | grep etc
>
>> There is the sshd that constrols the service. People are trying to
>> hack me. I did use this to turn it off.
>>
>> service sshd stop
>>
>> Which in turn caused systemctl to deactivate ssh(d).
>
> No it did not deactivate it, It did shut down the sshd service/daemon.
> Next boot, sshd will be running again.
>
>> Not can I turn this off by default?
>
> Yes, "systemctl disable sshd," disables sshd from being started during
> boot.
>
> You can still do a systemctl start sshd when you need it to run then
> systemctl stop sshd when done.
I logged on the other day and the shell told me that there was over 400
attempts by a certain IP address to connect. It must've been while I was
using the machine and didn't notice it.
Bill
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2014-10-10 08:50 +0000 |
| Message-ID | <m186ko$8na$1@dont-email.me> |
| In reply to | #12259 |
Bill Cunningham <nospam@nspam.invalid> wrote: > "Bit Twister" <BitTwister@mouse-potato.com> wrote in message > news:slrnm3e6v1.g24.BitTwister@wb.home.test... > > On Thu, 9 Oct 2014 19:23:11 -0400, Bill Cunningham wrote: > >> Hi, > >> > >> I can't find in fedora like there seems to be in other distros a > >> config file for ssh. > > > > It should not be hard to find, try > > locate ssh | grep conf | grep etc > > > >> There is the sshd that constrols the service. People are trying to > >> hack me. I did use this to turn it off. > >> > >> service sshd stop > >> > >> Which in turn caused systemctl to deactivate ssh(d). > > > > No it did not deactivate it, It did shut down the sshd > > service/daemon. Next boot, sshd will be running again. > > > >> Not can I turn this off by default? > > > > Yes, "systemctl disable sshd," disables sshd from being started > > during boot. > > > > You can still do a systemctl start sshd when you need it to run > > then systemctl stop sshd when done. > I logged on the other day and the shell told me that there was > over 400 attempts by a certain IP address to connect. It must've been > while I was using the machine and didn't notice it. > Bill That is most likely a brute force password attempt. If you shutdown ssh, you'll block the attempts, but also prevent yourself from logging in via ssh. So if you log in via ssh, you'll end up shutting yourself out as well. However, if your password is properly random, you have little to worry about other than extra entries in your log files. But if you want to block the attempts, you could install sshfaker (http://www.pkts.ca/ssh-faker.shtml) or fail2ban (http://www.fail2ban.org/wiki/index.php/Main_Page) and block the brute force password attempt, while leaving ssh open for yourself to use.
[toc] | [prev] | [next] | [standalone]
| From | Bit Twister <BitTwister@mouse-potato.com> |
|---|---|
| Date | 2014-10-10 09:10 +0000 |
| Message-ID | <slrnm3f8kc.k2m.BitTwister@wb.home.test> |
| In reply to | #12260 |
On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote: > > That is most likely a brute force password attempt. If you shutdown > ssh, you'll block the attempts, but also prevent yourself from logging > in via ssh. So if you log in via ssh, you'll end up shutting yourself > out as well. Just tell your firewall what ip addresses are allowed to connect to sshd. Tell sshd that root is not allowed to use a password login. Tell sshd to listen on a different port. > However, if your password is properly random, you have little to worry > about other than extra entries in your log files. Random passwords are easier to crack. Use a funky phrase like my dog eats concrete. Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2014-10-10 10:16 +0100 |
| Message-ID | <m18851$feb$1@news.albasani.net> |
| In reply to | #12261 |
On 10/10/14 10:10, Bit Twister wrote: > Random passwords are easier to crack. Blimey. Has anyone told GCHQ? -- Everything you read in newspapers is absolutely true, except for the rare story of which you happen to have first-hand knowledge. – Erwin Knoll
[toc] | [prev] | [next] | [standalone]
| From | "Bill Cunningham" <nospam@nspam.invalid> |
|---|---|
| Date | 2014-10-10 20:05 -0400 |
| Message-ID | <m19s7c$176$1@speranza.aioe.org> |
| In reply to | #12262 |
"The Natural Philosopher" <tnp@invalid.invalid> wrote in message
news:m18851$feb$1@news.albasani.net...
> On 10/10/14 10:10, Bit Twister wrote:
>> Random passwords are easier to crack.
>
>
> Blimey.
>
> Has anyone told GCHQ?
I'm lost on that one. Is that anything like LGBT ? ;)
Bill
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2014-10-11 07:47 +0100 |
| Message-ID | <m1ajpg$smd$2@news.albasani.net> |
| In reply to | #12281 |
On 11/10/14 01:05, Bill Cunningham wrote: > "The Natural Philosopher" <tnp@invalid.invalid> wrote in message > news:m18851$feb$1@news.albasani.net... >> On 10/10/14 10:10, Bit Twister wrote: >>> Random passwords are easier to crack. >> >> >> Blimey. >> >> Has anyone told GCHQ? > > I'm lost on that one. Is that anything like LGBT ? ;) > > Bill > > http://lmgtfy.com/?q=GCHQ -- Everything you read in newspapers is absolutely true, except for the rare story of which you happen to have first-hand knowledge. – Erwin Knoll
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2014-10-10 09:26 +0000 |
| Message-ID | <m188ng$ee8$1@dont-email.me> |
| In reply to | #12261 |
Bit Twister <BitTwister@mouse-potato.com> wrote: > On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote: > > However, if your password is properly random, you have little to > > worry about other than extra entries in your log files. > Random passwords are easier to crack. No. "properly random" means the password should look like this: =~dWx9C9pJq04lGMKh~C or this V064pb+e6)Sf/K?20/hf Which are not "easier to crack" but quite the opposite, significantly harder (note - the above two are not in use, and as they are randomly generated, never will be). > Use a funky phrase like > my dog eats concrete. > Feel free to sprinkle in numbers and !@#$%^&*()_+= characters. Not at all safe. The automatic crackers already know how to generate phrases with numbers and those characters sprinkled in, so that is actually easier to crack than a "properly random" password.
[toc] | [prev] | [next] | [standalone]
| From | The Natural Philosopher <tnp@invalid.invalid> |
|---|---|
| Date | 2014-10-10 11:00 +0100 |
| Message-ID | <m18ann$ksr$1@news.albasani.net> |
| In reply to | #12263 |
On 10/10/14 10:26, Rich wrote: > Bit Twister <BitTwister@mouse-potato.com> wrote: >> On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote: >>> However, if your password is properly random, you have little to >>> worry about other than extra entries in your log files. > >> Random passwords are easier to crack. > > No. "properly random" means the password should look like this: > > =~dWx9C9pJq04lGMKh~C > > or this > > V064pb+e6)Sf/K?20/hf > > Which are not "easier to crack" but quite the opposite, significantly > harder (note - the above two are not in use, and as they are randomly > generated, never will be). > >> Use a funky phrase like >> my dog eats concrete. >> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters. > > Not at all safe. The automatic crackers already know how to generate > phrases with numbers and those characters sprinkled in, so that is > actually easier to crack than a "properly random" password. > Try every word in the dictionary, then in combinations separated by 'unusual' characters, then with certain letters replaced by numbers. That's the starting point for a dictionary attack. -- Everything you read in newspapers is absolutely true, except for the rare story of which you happen to have first-hand knowledge. – Erwin Knoll
[toc] | [prev] | [next] | [standalone]
| From | Bit Twister <BitTwister@mouse-potato.com> |
|---|---|
| Date | 2014-10-10 10:14 +0000 |
| Message-ID | <slrnm3fcc3.k2m.BitTwister@wb.home.test> |
| In reply to | #12263 |
On Fri, 10 Oct 2014 09:26:08 +0000 (UTC), Rich wrote: > Bit Twister <BitTwister@mouse-potato.com> wrote: >> Random passwords are easier to crack. > > No. "properly random" means the password should look like this: > > =~dWx9C9pJq04lGMKh~C > > or this > > V064pb+e6)Sf/K?20/hf Yes I understood the word random. > Which are not "easier to crack" but quite the opposite, significantly > harder (note - the above two are not in use, and as they are randomly > generated, never will be). Frap, I can not find the article showing random password crack time was way less than a funky word string. Hardcore crackers are using several video card gpus to crack passwords. >> Use a funky phrase like >> my dog eats concrete. >> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters. > > Not at all safe. The automatic crackers already know how to generate > phrases with numbers and those characters sprinkled in, so that is > actually easier to crack than a "properly random" password. I completely agree with you with a single password. Since I can not find the article, we are at the end of this discussion. Now assuming Fedora 20 has a 3 second delay between each failed attempt, it is going to take quite awhile to finally hit on any reasonable strong phrase as the password. Just don't use any quote or current buzz words.
[toc] | [prev] | [next] | [standalone]
| From | Rich <rich@example.invalid> |
|---|---|
| Date | 2014-10-10 10:29 +0000 |
| Message-ID | <m18ce0$r77$1@dont-email.me> |
| In reply to | #12265 |
Bit Twister <BitTwister@mouse-potato.com> wrote:
> On Fri, 10 Oct 2014 09:26:08 +0000 (UTC), Rich wrote:
> > Bit Twister <BitTwister@mouse-potato.com> wrote:
> >> Random passwords are easier to crack.
> >
> > No. "properly random" means the password should look like this:
> >
> > =~dWx9C9pJq04lGMKh~C
> >
> > or this
> >
> > V064pb+e6)Sf/K?20/hf
> Yes I understood the word random.
> > Which are not "easier to crack" but quite the opposite, significantly
> > harder (note - the above two are not in use, and as they are randomly
> > generated, never will be).
> Frap, I can not find the article showing random password crack time was way
> less than a funky word string.
Here is one: How much time is needed to crack a password by
brute-force?
At the bottom of their "time table":
length: 10, complexity: a-zA-Z0-9 + symbols ==> 91800 years
> Hardcore crackers are using several video card gpus to crack passwords.
Which simply means you need to increase the length of your passwords to
compensate (that, and the services storing them need to use a proper
work adjustable password storage function like bcrypt or scrypt).
For whatever speed the gpu crackers achieve, there is a password length
that exceeds their capabilities. Which is why arbitrary length limits
on so many password protected services are actually more dangerous than
good. You are prevented from keeping pace with the gpu crackers.
[toc] | [prev] | [next] | [standalone]
| From | "Bill Cunningham" <nospam@nspam.invalid> |
|---|---|
| Date | 2014-10-10 16:27 -0400 |
| Message-ID | <m19ffh$58f$1@speranza.aioe.org> |
| In reply to | #12263 |
"Rich" <rich@example.invalid> wrote in message
news:m188ng$ee8$1@dont-email.me...
> Bit Twister <BitTwister@mouse-potato.com> wrote:
> Which are not "easier to crack" but quite the opposite, significantly
> harder (note - the above two are not in use, and as they are randomly
> generated, never will be).
I that depends on entropy and other things.
Bill
[toc] | [prev] | [next] | [standalone]
| From | William Unruh <unruh@invalid.ca> |
|---|---|
| Date | 2014-10-10 15:41 +0000 |
| Message-ID | <m18un5$la4$4@dont-email.me> |
| In reply to | #12261 |
On 2014-10-10, Bit Twister <BitTwister@mouse-potato.com> wrote: > On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote: >> >> That is most likely a brute force password attempt. If you shutdown >> ssh, you'll block the attempts, but also prevent yourself from logging >> in via ssh. So if you log in via ssh, you'll end up shutting yourself >> out as well. > > Just tell your firewall what ip addresses are allowed to connect to sshd. > Tell sshd that root is not allowed to use a password login. > Tell sshd to listen on a different port. > > >> However, if your password is properly random, you have little to worry >> about other than extra entries in your log files. > > Random passwords are easier to crack. Use a funky phrase like > my dog eats concrete. > Feel free to sprinkle in numbers and !@#$%^&*()_+= characters. He did say "properly random". I am sure by properly he did not mean 4 random characters. A long enough password with random characters is certainly better than your example which really is not terribly random.
[toc] | [prev] | [next] | [standalone]
| From | "Bill Cunningham" <nospam@nspam.invalid> |
|---|---|
| Date | 2014-10-10 20:03 -0400 |
| Message-ID | <m19s3t$148$1@speranza.aioe.org> |
| In reply to | #12270 |
"William Unruh" <unruh@invalid.ca> wrote in message
news:m18un5$la4$4@dont-email.me...
> On 2014-10-10, Bit Twister <BitTwister@mouse-potato.com> wrote:
>> On Fri, 10 Oct 2014 08:50:32 +0000 (UTC), Rich wrote:
>>>
>>> That is most likely a brute force password attempt. If you shutdown
>>> ssh, you'll block the attempts, but also prevent yourself from logging
>>> in via ssh. So if you log in via ssh, you'll end up shutting yourself
>>> out as well.
>>
>> Just tell your firewall what ip addresses are allowed to connect to sshd.
>> Tell sshd that root is not allowed to use a password login.
>> Tell sshd to listen on a different port.
>>
>>
>>> However, if your password is properly random, you have little to worry
>>> about other than extra entries in your log files.
>>
>> Random passwords are easier to crack. Use a funky phrase like
>> my dog eats concrete.
>> Feel free to sprinkle in numbers and !@#$%^&*()_+= characters.
>
> He did say "properly random". I am sure by properly he did not mean 4
> random characters. A long enough password with random characters is
> certainly better than your example which really is not terribly random.
Something generated by uuid would I think be pretty good. Or better yet
if you could direct something from dev/urandom as text; but I don't know if
you could do that.
Bill
[toc] | [prev] | [next] | [standalone]
| From | John Hasler <jhasler@newsguy.com> |
|---|---|
| Date | 2014-10-10 20:28 -0500 |
| Message-ID | <8761frbdii.fsf@thumper.dhh.gt.org> |
| In reply to | #12280 |
Bill Cunningham writes: > Something generated by uuid would I think be pretty good. Or better > yet if you could direct something from dev/urandom as text; but I > don't know if you could do that. Of course you could, but it's simpler to use a program such as pwgen. -- John Hasler jhasler@newsguy.com Dancing Horse Hill Elmwood, WI USA
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | comp.os.linux.misc
csiph-web