Alert!!

From: James Kosin (jkosin_at_beta.intcomgrp.com)
Date: 09/14/04

  • Next message: Jeremy Conlin: "Re: aic7xx system hangs"
    Date: Tue, 14 Sep 2004 09:27:42 -0400
    To: For users of Fedora Core releases <fedora-list@redhat.com>
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    Everyone,

    Just an update:
    ~ 1) I've noticed some traffic on the net recently trying to access
    port 111 (I have it blocked on my server). Those that don't know should
    really think about blocking this port from the outside using iptables.
    Be sure not to block your lo interface for this port.

    ~ 2) I've also made it so root can not login via ssh. This was to
    circumvent some of the problems with the recent sshd attacks. To block
    or not allow root to login, change the /etc/ssh/sshd_config file and add
    a line that has 'DenyUsers root'
    ~ This change does not block the attempt; but, it does block root from
    loging in. You can still login as a normal user and do an 'su -' to get
    root.

    Just a Kink Heads up,
    James Kosin
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.5 (MingW32)
    Comment: Using GnuPG with Thunderbird - http://enigmail.mozdev.org

    iD8DBQFBRvHNc7lFLjBWKW0RAnPQAJ4nNlcVdmU7qwl7gPBB0mGKVj7NWwCgib9I
    NgG0FkZCYG9hJHNKUX9aEi8=
    =GJTz
    -----END PGP SIGNATURE-----

    -- 
    fedora-list mailing list
    fedora-list@redhat.com
    To unsubscribe: http://www.redhat.com/mailman/listinfo/fedora-list
    

  • Next message: Jeremy Conlin: "Re: aic7xx system hangs"

    Relevant Pages

    • Re: Idea: "SSH Meeting"
      ... Some telnet allow no root login, maybe you can su - root. ... If you start telnetd in debug mode, a different port can be specified. ...
      (comp.os.linux.development.apps)
    • Re: Hardening a Solaris system.
      ... > I know files that execute with root permissions by normal users (e.g. ... > I've set up a web server, running Apache, so are thinking about what I ... thing to leave enabled in here might be a backup port. ... there are security steps here. ...
      (comp.unix.solaris)
    • Re: Hardening a Solaris system.
      ... > I know files that execute with root permissions by normal users (e.g. ... > I've set up a web server, running Apache, so are thinking about what I ... thing to leave enabled in here might be a backup port. ... there are security steps here. ...
      (comp.security.unix)
    • Re: SSH pubkey or password based on user group
      ... What I was trying to do is not to allow users that are in root group to ... every other user can choose whether they will login using their password ... only on another port, with your sshd set something like this: ... Manipulating a single SSH daemon to do what you ...
      (comp.security.ssh)
    • Re: SSH security questions
      ... My solution is to set my firewall to remap a non-standard port to port 22 ... the firewall maps 2002 to 22). ... One must login with a real ID then su over to root. ...
      (comp.os.linux.security)