Re: Securing SSH: Does disabling password authentication work?

From: Steve Block (scblock_at_ev-15.com)
Date: 10/03/05

  • Next message: Jerome BENOIT: "Re: back Up in CD"
    Date: Mon, 3 Oct 2005 14:49:01 -0500
    To: debian-user@lists.debian.org
    
    

    On Mon, Oct 03, 2005 at 10:47:27AM -0700, Alvin Oga wrote:
    >
    >hi ya steve
    >
    >On Mon, 3 Oct 2005, Steve Block wrote:
    >
    >> login attempts were reported as one of
    >>
    >> faileduser/password from ip.addr.
    >>
    >> or
    >>
    >> faileduser/none from ip.addr.
    >>
    >> >From the logs I've looked at after I changed my SSH configuration, I now
    >> only see the latter, perhaps because the password authentication method
    >> is no longer available.
    >
    >are you saying that you still get ssh log entries ??
    >
    ><sticking my bloody toe into a hungry shark filled pond>
    >if so, sshd is still responding to incoming ssh connection on other ports
    ></toe>
    >
    >> Of course nothing is bulletproof but am I actually more
    >> secure than before?
    >
    >no
    >
    >... you made no other security changes other than port# which can
    >trivially be changed to do exactly the same port 22 attacks on other ports

    I'm afraid you didn't read at all, did you? Start from the top of the
    thread and read again, and you'll see that my question had nothing to do
    with port numbers at all. I'm asking if disabling password
    authentication while leaving keyboard-interactive/pam and publickey
    methods available would pretty much leave the current automated attacks
    high and dry since they use password based connection attemps.

    -- 
    Steve Block
    http://ev-15.com/
    http://steveblock.com/
    scblock@ev-15.com
    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Jerome BENOIT: "Re: back Up in CD"

    Relevant Pages

    • Re: Need SMTP Server
      ... Thank you very much much Steve. ... What I got from this Sanford character seemed to be more in the form of abuse and distain. ... These forums should be public forums where one goes for help on a subject. ... Change the SMTP port to 587 and send yourself a test message to your gmail account, ...
      (microsoft.public.inetserver.iis.smtp_nntp)
    • Re: Opening a specific TCP port on a Netscreen 5XT
      ... > Steve wrote: ... Objects/Services create a new Custom service for the port and protocol ... Create a new VIP instance on your untrust IP. ... Create a new VIP service specifying the internal IP of the destination ...
      (comp.security.firewalls)
    • Re: Unable to initialize device prn
      ... Thanks so far to both Anonymous and Steve. ... On my old pc I can print from command promt - but from the new pc, ... So do you know how I can configure the port or configure command promt - so ... If LPT3 gives you an error then just replace it with LPT. ...
      (microsoft.public.office.misc)
    • Re: Windows 2000 Terminal Server and Printers
      ... Steve ... > point it to our print server. ... > choose local port. ... >> I have tried installing the printer as a local administrator on the ...
      (microsoft.public.win2000.general)
    • Re: Port 137 Hammering
      ... :) Geesh. ... >>60 inbound port 137 hits every hour, ... >>forgotten worm with a date trigger or is this something new? ... >>Steve Z. ...
      (comp.security.firewalls)