On CHOW: Throw parties like a pro
BNET Business Network:
BNET
TechRepublic
ZDNet
TalkBack 1 of 23:
Next »
Just a few google hacks is all it takes to return sites
Example: "intitle:index of" passwords modified

Your site shouldn't return anything for a google on "intitle:index of" and inurl:

As for sftp (ssh), be sure that your server's /etc/sshd_config is set for:

PermitRootLogin no
UsePAM no
ChallengeResponseAuthentication no
Port 62314 #example of some non-standard port

Create a publickey with ssh-keygen for passwordless login.

I spent last reviewing my logs to find that there appears to be a new 'distributed' ssh brute force attack method which will fly below 'the radar' of most intrusion detection systems.

DenyHosts is installed on my servers but this distributed brute-force technique relies on sending each successive login attempt from a different ip separated by about 30 seconds or more.

As such Denyhosts fails to sense the attack because it doesn't see just 'one ip' failing 5 times.

Follow the above ssh configuration changes to secure your system from any brute-force attack--the only way.

Also, if you run an unmanaged site, and it runs on any Linux Distro, please install AppArmor and mod-apparmor Apache module (AppArmor is standard equipment in openSUSE 10.3 and Ubuntu 8.04).

Here's an Ars Technica article that hightlights last weeks ssh attacks:

http://arstechnica.com/news.ars/post/20080515-strong-passwords-no-panacea-as-ssh-brute-force-attacks-rise.html

Be safe!
Posted by: D. T. Schmitz   Posted on: 05/18/08 You are currently: a Guest | Members login | Terms of Use

Alert moderator to an offensive message

Subscribe to this discussion via Email or RSS

Just a few google hacks is all it takes to return sites  D. T. Schmitz | 05/18/08
FTPS is also a very viable solution  georgeou | 05/18/08
RE: If hackers don't get you, maybe Google will  rrubr@... | 05/18/08
So Robin, do you know exactly HOW you were hacked!?  Scrat | 05/19/08
"Don't Be Evil" Expired the second they went public...  BitTwiddler | 05/19/08
Google has a monopoly on search?  Vesicant | 05/19/08
The Linux fanboys...  Marty R. Milette | 05/19/08
Right but the difference  Real World | 05/19/08
But they were not a monopoly  GuidingLight | 05/19/08
Yes, you're correct  Real World | 05/19/08
Good Point...nt  socialism=nowhere | 05/19/08
The nature of the situation...  kouzen | 05/19/08
The reason is mentioned in your post  GuidingLight | 05/19/08
Umm...  JDThompson | 05/19/08
Blame Google? Blame yourself.  I_am_windex007@... | 05/19/08
Blame Google? Why not?  Gradius2 | 05/19/08
Who to blame???  Narg | 05/19/08
Still Robin.  I_am_windex007@... | 05/19/08
RE: If hackers don't get you, maybe Google will  I_am_windex007@... | 05/19/08
I agree 100%  floridait@... | 05/20/08
Google or search engines are less important today  PhilippeV | 05/19/08
Scorched Earth approach to...  thx-1138_@... | 05/20/08
amen  catseverywhere@... | 07/16/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
advertisement

SmartPlanet

Click Here