nrspot.com

Open Source , Linux , Firewall , Wireless , WiMax , Security , IT
Subscribe to RSS feed

« Linux availability Cluster
Wimax Indonesia , Goes near . »

Brute Force Attack SSH bomb protection using Shorewall

Just found some error log messages in /var/log/secure that shows me so many ssh bom attack just got into intrnet server gateway. 

all you need to do if you enable ssh connection to your linux box that you have to disable root login first, you could find and edit the configurations of your ssh config , like this :

1. SSH into your server as root

2. Copy and paste this line to edit the file for SSH logins   

vi /etc/ssh/sshd_config

3.  find the line
PermitRootLogin yes

3. Uncomment it and make it look like PermitRootLogin no 

4 Save the file 
5. Now you can restart SSH
/etc/rc.d/init.d/sshd restart

if you are using shorewall configuration, because the attacker always using the same method in attacking process, which means this method related to some interval time to handle the login attempt, you need to modify your shorewall configuration in /etc/shorewall/rules ,

put this configuration on your /etc/shorewall/rules :

Limit:info:SSHA,3,60   net               $FW            tcp         22
 

# 3 logins attempt in 60 seconds..

ok, enough by now.

Good luck

This entry was posted on Friday, March 13th, 2009 at 12:52 am and is filed under Music, Security. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.

Leave a Reply

You must be logged in to post a comment.

  • www.Metrochip8.com Toko Komputer Online

    ads3kecil.jpgKomputer, Printer, Notebook, Network & Aksesoris, Harga Murah Diskon.
  • Recent Posts

    • Aplikasi Human Resource Development & penggajian menggunakan Open Source
    • Cuma 2 Operator yang Penuhi Kewajiban Wimax
    • Postel: Wimax TRG Penuhi Syarat TKDN
    • 2010, TRG Bangun Pabrik Wimax Rp 65 Miliar di Jababeka
    • 2009 / Sun / MySQL / Open Source
    • Produk Wimax, BTS, CPE, EMS Server dari trg.co.id
    • Nokia N810 menggunakan Linux Maemo 4 dan bisa mengakses Wimax.
    • Green SQL & Perlindungan terhadap SQL Injection Attack
    • PT. LEN ( Lembaga Elektronika Nasional) ikut memproduksi perangkat WiMax
    • Menkominfo Tanggung Jawab Jika BWA & WiMAX Gagal Berjalan
  • Categories

    • Anti Virus
    • Fashion
    • Hardware
    • Linux
    • Lowongan Kerja
    • Music
    • Networking
    • Open Source
    • Security
    • Sistem Informasi
    • Software
    • Sport
    • Wimax
    • Wireless
  • Pages

    • About
    • Komputer & Aksesoris
    • Product
  • Spam Blocked

    108 spam comments
    blocked by
    Akismet
  • Blogroll

    • Cisco System
    • donalda
    • Fedora Linux
    • Linux Centos
    • Metropolar Komputer / Metrochip8
    • Narcist Union
    • Narcist Union Blog
    • Narcit Union , Genuine Leather, Wallet Dompet, Tas, Bahan Kulit
    • Redhat Linux
    • Smart Surabaya
  • RSS Linux

    • Qmail OpenLdap On Ubuntu
    • Installing Apache2 With PHP5 And MySQL Support On Mandriva 2010.1 Spring (LAMP)
    • vtiger Installation On CentOS 5.x
    • How To Set Up Apache2 With mod_fcgid And PHP5 On Ubuntu 10.04
    • ISPConfig3 - DNS Templates
  • RSS Fedora

    • Virtual Hosting With PureFTPd And MySQL (Incl. Quota And Bandwidth Management) On Fedora 13
    • Integrating XCache Into PHP5 (Fedora 13/CentOS 5.5 & Apache2)
    • Integrating APC (Alternative PHP Cache) Into PHP5 (Fedora 13 & Apache2)
    • Fedora 13 Samba Standalone Server With tdbsam Backend
    • Installing Lighttpd With PHP5 And MySQL Support On Fedora 13
  • Meta

    • Login
    • Entries RSS
    • Comments RSS
    • WordPress.org
  • Alexa


Copyright © nrspot.com - Powered by WordPress
ProSense theme created by Dosh Dosh and The Wrong Advices.