Members
  • Total Members: 14176
  • Latest: toxxxa
Stats
  • Total Posts: 42953
  • Total Topics: 16150
  • Online Today: 4867
  • Online Ever: 51419
  • (01. January 2010., 10:27:49)









Author Topic: SSH server attacks resurface  (Read 2292 times)

0 Members and 1 Guest are viewing this topic.

georgecloner

  • SCF VIP Member
  • *****
  • Posts: 171
  • KARMA: 16
  • Gender: Male
SSH server attacks resurface
« on: 19. April 2009., 14:29:04 »


Security researchers are warning administrators to secure their servers in the wake of new Secure Shell (SSH) attacks.

Researchers at security firm SANS warned that so-called 'brute force' attacks were occurring on a "daily" basis. The attacks attempt to guess usernames and passwords in an attempt to compromise the server.

To help guard against the attacks, SANS researcher Daniel Weseman recommended that administrators help guard against the attacks by making both usernames and passwords more difficult for attackers to guess.

"If you are running any SSH server open to the Internet, and your usernames and passwords aren't at least 8 characters or so, your box is either owned by now, or about to be," explained Wesemann.

"It doesn't matter one bit what sort of device it is - those who run these scans have proven to be equally apt at taking over a Cisco router as they are at subverting an iMac."

In addition to complicating usernames and passwords, Weseman also suggested that administrators use other simple measures such as moving SSH off of port 22 and monitor logs for suspicious activity. While the measures will not prevent an attack, Weseman said that they would at least make compromising a machine for difficult.

"Yes we know that picking complicated usernames and moving SSH off port 22 are 'security by obscurity' and not real security," Weseman admitted.

"But fact is that they both help to thwart the rampant brute force attacks. Bulletproof is nice, but if it can't be had, good camouflage sure beats being a plum target!"

VNUNET
Creativity is a mental and social process involving the generation of new ideas or concepts, or new associations of the creative mind between existing ideas or concepts.

Samker's Computer Forum - SCforum.info

SSH server attacks resurface
« on: 19. April 2009., 14:29:04 »

 

With Quick-Reply you can write a post when viewing a topic without loading a new page. You can still use bulletin board code and smileys as you would in a normal post.

Name: Email:
Verification:
Type the letters shown in the picture
Listen to the letters / Request another image
Type the letters shown in the picture:
Second Anti-Bot trap, type or simply copy-paste below (only the red letters):www.scforum.info:

Enter your email address to receive daily email with 'SCforum.info - Samker's Computer Forum' newest content:

Terms of Use | Privacy Policy | Advertising