I am going to set-up a little server at my home and I am learning stuff about how to prevent hacker parties inside while it is running. I think that since now I’ve made an acceptable work (I just set up two firewalls in front of it, and got other precautions), but prudence is never too much.
The latest interesting stuff found on this topic is about gaining control over ssh connections, avoiding dictionary attacks, and other problems: for example – also ssh can have bugs – disallowing root from login is always good thing. Really nice hints comes from Security Paranoia – restricting ssh access blog by Tony Lawrence.
Due to this useful information, I just subscribed his weblog. Great stuff!
Update:
Other things that could be done:
Disable password authentication commenting out UsePAM (by default is set to no):
#UsePAM yes
Indicate which users are allowed to connect:
AllowUsers scott
If you only want to use SSH 2 protocol (that is more secure), you can disable RSA authentication:
RSAAuthentication no
For more info:
$ man sshd_config
Search
Calendar
| M | T | W | T | F | S | S |
|---|---|---|---|---|---|---|
| « Jul | Sep » | |||||
| 1 | 2 | 3 | 4 | 5 | 6 | 7 |
| 8 | 9 | 10 | 11 | 12 | 13 | 14 |
| 15 | 16 | 17 | 18 | 19 | 20 | 21 |
| 22 | 23 | 24 | 25 | 26 | 27 | 28 |
| 29 | 30 | 31 | ||||
Archives
Categories
- Android (3)
- Apple (27)
- Books (7)
- Eclipse (14)
- Errors (4)
- Firefox (7)
- Git (2)
- Hardware (17)
- Horror Code (8)
- Internet (21)
- Java (102)
- JavaScript (9)
- Life, universe and everything (46)
- Lifehacks (25)
- Linux (51)
- Opinions (26)
- OSX (6)
- Python (1)
- Software (31)
- Speeches and Conferences (8)
- Unix (4)
- Web (23)
- Windows (19)
Tag Cloud
Android apple architecture Bash configuration CSS Development Düsseldorf Eclipse Git Google Hardware hdr How-To Java JAXB job junit Karmic Linux lion MacBook music Open Source Opinion oracle OSX patterns Pitfalls Practices Resume Security Software Suspend TDD Testing tip tonemapped Tricks Ubuntu unix video Web Workaround XML
WP Cumulus Flash tag cloud by Roy Tanck and Luke Morton requires Flash Player 9 or better.
Blog License
Blogs I like
Books on the desk
Friends' Blogs
- Antonio Terreno & Valter Bernardini
- Bruno Bossola
- Daniele Galluccio
- Domenico Ventura
- Ed Schepis
- Fabrizio Gianneschi
- Luca Grulla
- Luigi Zanderighi
- Marcello Teodori
- Mida Boghetich
- Muralidharan Chandrasekaran
- Piero Ricca
- Renzo Borgatti
- Simone Bordet
- Simone Bruno
- Uberto Barbini
- Valvolog
- Webtide blogs (Greg Wilkins & Jan Bartel)
Links




















One Response to “Security paranoia: restricting ssh access”
Please Wait
Leave a Reply