stopping C2 security account lockout on root via SSH

From: Mike Broderick (mikebroderick_at_gmail.com)
Date: 01/27/05

  • Next message: Dr. Martin Körfer: "rsync-question"
    Date: Wed, 26 Jan 2005 20:40:29 -0500
    To: tru64-unix-managers@ornl.gov
    
    

    I have a couple Tru64 boxes (4.0f and 5.1b) both using C2 security
    that get occasional root login attacks via SSH. These attacks (3000
    hits on root last time) cause the root account to get locked. I tried
    disabling root logins from SSH with "PerminRootLogins no" (in
    sshd_config) but I still see failed attempts logged in the auth db
    (u_numunsuclog for root user increments). I then tried adding
    "DenyUsers root" too which seems to work on the 4.0f system but not on
    5.1b. I do get an "invalid user" error in the auth.log in both but on
    5.1b u_numunsuclog still increments.

    The Tru64 delivered ssh is not beig used, but rather a version of
    OpenSSH manually downloaded/built. (4.0f has OpenSSH 3.1p1 and 5.1b
    has 3.7.1p2) The 5.1b system was just upgraded from 5.1a to 5.1b.

                                                                          
                 _Mike


  • Next message: Dr. Martin Körfer: "rsync-question"

    Relevant Pages

    • RE: Linux hacked
      ... Also, what exactly did the history file show, can you paste it into a mail ... > First let me say I'm a security novice. ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
      (Security-Basics)
    • Re: Linux hacked
      ... To find out what kernel version you are running, type "uname -a" without ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
      (Security-Basics)
    • RE: Linux hacked
      ... hack the box, pull the drive and save it. ... Use the newest versions of Gentoo, Apache, SSH, PHP and Squirl Mail. ... been unsuccessful in getting root back. ... I found a hidden directory /var/tmp/.tmp that has a bunch of directories ...
      (Security-Basics)
    • RE: Linux hacked
      ... Was any of the sites running a php nuke or another portal or system that is vuln ... been able to use that with a locla root exploit to gain root on the machine. ... > hack the box, pull the drive and save it. ... > Use the newest versions of Gentoo, Apache, SSH, PHP and Squirl Mail. ...
      (Security-Basics)
    • Re: X11Forwarding, ssh -X, and /bin/su
      ... ]>but I'm not really tunneled using ssh then, ... ]connecting to the X server and have the home directory NFS-mounted ... ](unless you leave root unmapped over NFS, ... ]root-readable place and set the environment $XAUTHORITY variable ...
      (comp.security.ssh)