ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    I'm under attack I need help in ssh

    IT Discussion
    7
    26
    6.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stacksofplatesS
      stacksofplates
      last edited by

      Also what PBX is this? Is it FreePBX?

      1 Reply Last reply Reply Quote 0
      • coliverC
        coliver
        last edited by coliver

        Would be a good idea to setup fail 2 ban as well.

        stacksofplatesS T 2 Replies Last reply Reply Quote 3
        • T
          tiagom
          last edited by

          From the original post looks like you are using dropbear ssh.. config should be /etc/config/dropbear

          Looks like you need to set

          option PasswordAuth 'off'
          

          https://wiki.openwrt.org/doc/uci/dropbear has more details as i couldn't (quickly) find official documentation.

          stacksofplatesS 1 Reply Last reply Reply Quote 0
          • stacksofplatesS
            stacksofplates @coliver
            last edited by

            @coliver said in I'm under attack I need help in ssh:

            Would be a good idea to setup fail 2 ban as well.

            I hope at some point in the future they make the setup a little easier. It's fairly daunting for a new person. Pam_tally2 and faillock are fairly easy to set up, but rely on PAM. Would be nice to have a middle ground.

            1 Reply Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates @tiagom
              last edited by

              @tiagom said in I'm under attack I need help in ssh:

              From the original post looks like you are using dropbear ssh.. config should be /etc/config/dropbear

              Looks like you need to set

              option PasswordAuth 'off'
              

              https://wiki.openwrt.org/doc/uci/dropbear has more details as i couldn't (quickly) find official documentation.

              Good catch, I didn't notice that.

              1 Reply Last reply Reply Quote 0
              • T
                tiagom @coliver
                last edited by

                @coliver said in I'm under attack I need help in ssh:

                Would be a good idea to setup fail 2 ban as well.

                Agreed.

                1 Reply Last reply Reply Quote 0
                • I
                  inroute
                  last edited by

                  there is no config folder in the /etc/ directory but i found dropbear folder in the /etc/ directory and it contain tow files

                  dropbear _dss_host_key
                  dropbear _rsa_host_key

                  any idea

                  1 Reply Last reply Reply Quote 0
                  • T
                    tiagom
                    last edited by

                    What about under /etc/default/dropbear

                    What distro and pbx are you running so we can stop guessing.

                    I 2 Replies Last reply Reply Quote 0
                    • I
                      inroute @tiagom
                      last edited by

                      @tiagom no there no under /etc/default/dropbear

                      sorry Tiagom im new in Linux
                      the pbx is Panasonic gsm gateway

                      1 Reply Last reply Reply Quote 0
                      • I
                        inroute @tiagom
                        last edited by

                        @tiagom Linux version 3.0.76-4.i586 gcc version 4.4.1 ( GCC)

                        1 Reply Last reply Reply Quote 0
                        • T
                          tiagom
                          last edited by tiagom

                          It looks like you need to set

                           DROPBEAR_EXTRA_ARGS="-s"
                          

                          in the dropbear init file.

                          https://github.com/mkj/dropbear/blob/master/debian/dropbear.init

                          *It states Do not configure this file. Edit /etc/default/dropbear instead! in the latest version. Your version maybe older or modified by panasonic since /etc/default/dropbear doesnt exist..

                          Arg found here

                          http://linux.die.net/man/8/dropbear

                          But honestly, if there is a firewall in front of this pbx box it maybe easier to do it there.

                          I 2 Replies Last reply Reply Quote 0
                          • I
                            inroute @tiagom
                            last edited by

                            @tiagom so what do you think i must do to stop hackers and right now one hacker he made the gateway reboots like 100 time

                            is there a way that i can block him

                            scottalanmillerS 1 Reply Last reply Reply Quote 0
                            • I
                              inroute @tiagom
                              last edited by

                              @tiagom please see this link
                              http://manpages.ubuntu.com/manpages/precise/man8/dropbearkey.8.html

                              do you think it will help and honestly if you can guide me on how to do it .
                              it will be nice from you

                              1 Reply Last reply Reply Quote 0
                              • T
                                tiagom
                                last edited by tiagom

                                Its difficult to suggest without knowing the environment..

                                The simplest is change passwords if its compromised.

                                If its behind a firewall you can block traffic on port 22 unless its from your ip..

                                I 1 Reply Last reply Reply Quote 2
                                • I
                                  inroute @tiagom
                                  last edited by

                                  @tiagom ummmm....

                                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                                  • JaredBuschJ
                                    JaredBusch @inroute
                                    last edited by

                                    @inroute said in I'm under attack I need help in ssh:

                                    @tiagom ummmm....

                                    @tiagom is exactly right. You have a Panasonic device on your network, it should be behind your router/firewall, so just turn off port 22 at your router/firewall.

                                    tonyshowoffT 1 Reply Last reply Reply Quote 3
                                    • scottalanmillerS
                                      scottalanmiller @inroute
                                      last edited by

                                      @inroute said in I'm under attack I need help in ssh:

                                      @tiagom GNU/Linux

                                      That's a family but not an OS. OS would be like CentOS, Ubuntu, etc.

                                      tonyshowoffT 1 Reply Last reply Reply Quote 2
                                      • scottalanmillerS
                                        scottalanmiller @inroute
                                        last edited by

                                        @inroute said in I'm under attack I need help in ssh:

                                        @tiagom so what do you think i must do to stop hackers and right now one hacker he made the gateway reboots like 100 time

                                        is there a way that i can block him

                                        @inroute said in I'm under attack I need help in ssh:

                                        @tiagom so what do you think i must do to stop hackers and right now one hacker he made the gateway reboots like 100 time

                                        is there a way that i can block him
                                        What is the gateway? It's just an Ubuntu server?

                                        1 Reply Last reply Reply Quote 0
                                        • tonyshowoffT
                                          tonyshowoff @scottalanmiller
                                          last edited by tonyshowoff

                                          @scottalanmiller said in I'm under attack I need help in ssh:

                                          @inroute said in I'm under attack I need help in ssh:

                                          @tiagom GNU/Linux

                                          That's a family but not an OS. OS would be like CentOS, Ubuntu, etc.

                                          GNU/Linux is pig tail riding on behalf of Richard Stallman. If it's GNU/Linux, then this is actually not MangoLassi, but NodeBB/MangoLassi, and WordPress is Zend/WordPress. Funny how nobody else on the entire planet other than Stallman makes a requirement of software using libraries he hasn't contributed to in 30 years.

                                          </my non-contribution to conversation>

                                          1 Reply Last reply Reply Quote 2
                                          • tonyshowoffT
                                            tonyshowoff @JaredBusch
                                            last edited by

                                            @JaredBusch said in I'm under attack I need help in ssh:

                                            @inroute said in I'm under attack I need help in ssh:

                                            @tiagom ummmm....

                                            @tiagom is exactly right. You have a Panasonic device on your network, it should be behind your router/firewall, so just turn off port 22 at your router/firewall.

                                            Better yet, do that, and change the port of sshd all together to something much higher. Yes, it's sort of "security through obscurity," but it will avoid constant bot attacks and so forth, but anyone directly wanting to attack the machine can easily find the information if it's open to the public Internet.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 1 / 2
                                            • First post
                                              Last post