 |
 |
 |
 |
| Wibble A place to have a sensible chat, about anything non linux related. Please remember that political and religious topics are not permitted. |

24th November 2008, 03:25 AM
|
|
Registered User
|
|
Join Date: Jul 2008
Location: London
Posts: 77

|
|
Linux hack
My friend demonstrated linux loopholes (which he never told me)
he just asked my IP address, I gave.
Chk what happened next:
http://i38.tinypic.com/2r5uy3d.jpg
ps aux displayed no other processes than the once going in my logic...
He mentioned something related to sshd, now what is that, i dunno!
Chk the upload speed.... I never got download speed this much!
__________________
Keval Domadia
Suspense behind each distro is:
................ tell you later!
Last edited by kevaljd; 24th November 2008 at 03:34 AM.
|

24th November 2008, 03:28 AM
|
|
Guest
|
|
Posts: n/a

|
|
|
thats called advertising IMO,, you should know thats not allowed on the forum
|

24th November 2008, 03:32 AM
|
|
Registered User
|
|
Join Date: Jul 2008
Location: London
Posts: 77

|
|
Hey Demz..
There seems to be a misunderstanding...
I thought I would attach file on my hosting site and then share it... but it just aint workin seriously got no idea... will edit it in a bit.....
EDIT:
DONE! Now u can chk the link above and see it urself
__________________
Keval Domadia
Suspense behind each distro is:
................ tell you later!
Last edited by kevaljd; 24th November 2008 at 03:36 AM.
|

24th November 2008, 03:36 AM
|
|
Guest
|
|
Posts: n/a

|
|
Quote:
Originally Posted by kevaljd
Hey Demz..
There seems to be a misunderstanding...
I thought I would attach file on my hosting site and then share it... but it just aint workin seriously got no idea... will edit it in a bit..... 
|
you cant attach files or pictures direct from your PC an upload to the forum
nothing about hacking on this forum is tolerated, so if it is,, this thread will be sent straight to trash
Last edited by Demz; 24th November 2008 at 03:41 AM.
|

24th November 2008, 04:31 AM
|
|
Registered User
|
|
Join Date: Jul 2008
Location: London
Posts: 77

|
|
ok cool!
no issues..
go on...
I dunno how to delete thread...

just wanted to share some things that 99% people don't know
__________________
Keval Domadia
Suspense behind each distro is:
................ tell you later!
|

24th November 2008, 09:07 PM
|
 |
Registered User
|
|
Join Date: Apr 2006
Location: North West UK.
Age: 32
Posts: 510

|
|
|
That looks to me like a syn flood attack, iptables will take care of that, just google it. You should also be asking why your SSHd is open to the internet anyway, even my webserver's have SSHD locked down to just a few IP addresses.
__________________
He who asks a question is a fool for a minute; he who does not remains a fool forever.
|

24th November 2008, 09:46 PM
|
 |
Registered User
|
|
Join Date: Oct 2008
Location: England, Lincolnshire
Posts: 1,576

|
|
|
I think you will find that is only insecure, because of your self. not the OS. you can EASILY block those minor tricks.
__________________
Fedora user since FC6.
Linux user since 2003.
Registered Linux ID: #456478
OS: Fedora 16 x86_64
|

24th November 2008, 11:52 PM
|
|
Registered User
|
|
Join Date: Jul 2008
Location: London
Posts: 77

|
|
Quote:
Originally Posted by JakeS
I think you will find that is only insecure, because of your self. not the OS. you can EASILY block those minor tricks.
|
In a way, I buy your point!
I confirmed with my friend. He did it through SSHD and tricked me as he got the correct GUESS of my root password. He did a replication of my hard disk to his hard disk. What amazed me is the speed at which packets were SHOOTING... I have never seen anything like this before so I captured it on the spot.
__________________
Keval Domadia
Suspense behind each distro is:
................ tell you later!
|

25th November 2008, 12:37 AM
|
|
Clueless in a Cuckooland
|
|
Join Date: Mar 2006
Location: Here now, elsewhere tomorrow.
Posts: 3,929

|
|
Quote:
Originally Posted by kevaljd
In a way, I buy your point!
I confirmed with my friend. He did it through SSHD and tricked me as he got the correct GUESS of my root password. He did a replication of my hard disk to his hard disk. What amazed me is the speed at which packets were SHOOTING... I have never seen anything like this before so I captured it on the spot.
|
Few lessons you can learn from this:
1- NEVER allow root logins on SSH
2- ALWAYS use STRONG, un-guessable root password
3- ALWAYS use key-based authentication for SSH.
4- NEVER leave any ports you don't need, open in your firewall
5- ALWAYS disable unused services
Implement 1 to 3 if you need SSH server running on your box and ask your friend to try again and see what happens.
Additionally you can run, for example, denyhosts to automatically block IP addresses after set number of failed connection attempts etc.
|

25th November 2008, 04:47 AM
|
 |
An ape descendant
|
|
Join Date: Dec 2006
Location: Mexico City
Age: 29
Posts: 3,101

|
|
Quote:
Originally Posted by pete_1967
Few lessons you can learn from this:
1- NEVER allow root logins on SSH
2- ALWAYS use STRONG, un-guessable root password
3- ALWAYS use key-based authentication for SSH.
4- NEVER leave any ports you don't need, open in your firewall
5- ALWAYS disable unused services
Implement 1 to 3 if you need SSH server running on your box and ask your friend to try again and see what happens.
Additionally you can run, for example, denyhosts to automatically block IP addresses after set number of failed connection attempts etc.
|
Apparently that is Ubuntu, so it might not have been that hard (sudo).
Thanks.
Joe.
__________________
Notebook: Acer Aspire 5536-5112.
AMD Athlon X2 QL64 @ 2.1GHz, 4GB DDR2 PC2-5300, ATI Radeon HD3200 (256MB), 250GB Toshiba HDD, HL-DT-ST DVDRAM GT20N
Fedora 16 x86_64
Netbook: Acer Aspire One A150
Intel Atom N270 @ 1.6GHz, 1.5 GB DDR2 PC2-4200, Intel Graphics (8MB?), 160GB Seagate HDD
Fedora 15 i686
|

25th November 2008, 07:46 AM
|
 |
Banned (for/from) behaving just like everybody else!
|
|
Join Date: Jul 2007
Location: Beijing, China
Posts: 1,307

|
|
+1 for denyhosts
You know, using password-based authentication for SSH is always a BAD IDEA. It only checks something you know (the password). The advantage of key-based authentication is that you have to provide something you know (the passphrase to decrypt the key) AND something you have (the key).
I recommend you read this fine article by Bruce Schneier: http://www.schneier.com/blog/archive...ng_secure.html
You'll see how easy it is to crack an average password now.
Your friend gave you a very good lesson. Personally I'm amazed to see that you had *not* been cracked like this before. (Or perhaps you have been, but you just didn't know it). In August I spend a month at my home town where I used a local ISP's ADSL service so I got a public IP address. In the very first day, I discovered some presumably rooted hosts trying to crack me like crazy. They tried my root and a bunch of other username's passwords like several thousand times in a few hours (which was in vain). In the next days I just watched my denyhosts blacklist growing and growing...
Another tip: create a group like "ssh_denied", and put everyone you don't wish to grant remote login for in the group, no matter human users or non-human ones. Put the line in your SSHD configuration file: "Denygroups sshd_denied".
__________________
I believe in nerditarianism. I read FedoraForum for the Fedora-related posts.
|
| Thread Tools |
Search this Thread |
|
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
Current GMT-time: 23:38 (Wednesday, 22-05-2013)
|
|
 |
 |
 |
 |
|
|