All the latest UK technology news, reviews and analysis

SSH server attacks resurface

by Shaun Nichols

18 Apr 2009

Comment: 1

  • Tweet this
lockdown
Admins are being urged to use tougher usernames and passwords

Security researchers are warning administrators to secure their servers in the wake of new Secure Shell (SSH) attacks.

Researchers at security firm SANS warned that so-called "brute force" attacks were occurring on a daily basis. The attacks attempt to guess usernames and passwords in order to compromise the server.

To help guard against the attacks, SANS researcher Daniel Wesemann recommended that administrators try to make both usernames and passwords more difficult for attackers to guess.

"If you are running any SSH server open to the internet, and your usernames and passwords aren't at least eight characters or so, your box is either owned by now, or about to be," explained Wesemann.

"It doesn't matter one bit what sort of device it is - those who run these scans have proven to be equally apt at taking over a Cisco router as they are at subverting an iMac."

In addition to complicating usernames and passwords, Wesemann also suggested that administrators use other simple measures such as moving SSH off of port 22 and monitor logs for suspicious activity. While the measures will not prevent an attack, Wesemann said that they would at least make compromising a machine more difficult.

"Yes we know that picking complicated usernames and moving SSH off port 22 are 'security by obscurity' and not real security," Wesemann admitted. "But fact is that they both help to thwart the rampant brute force attacks. Bulletproof is nice, but if it can't be had, good camouflage sure beats being a plum target!"

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

34%

1%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Global Project/Programme Manager-with recruitment deployment experienc

My London client is looking for an experienced Programme...

PHP Developers (All Levels)

My leading client is looking for a number of excellent...

Group Services Manager - Telecoms

My client, a leading international name in Manufacturing...

Automated PHP Developer

My client is looking for an Automated Engineer/Developer...

To send to more than one email address, simply separate each address with a comma.