Unix Technical Forum

pam, ssh, user account vulnerability

This is a discussion on pam, ssh, user account vulnerability within the Linux Operating System forums, part of the Unix Operating Systems category; --> So, to give a bit of resolution: I discovered why the PAM settings didn't seem to apply. Turns out ...


Go Back   Unix Technical Forum > Unix Operating Systems > Linux Operating System

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #11 (permalink)  
Old 01-18-2008, 09:40 AM
Lenny G.
 
Posts: n/a
Default Re: pam, ssh, user account vulnerability

So, to give a bit of resolution: I discovered why the PAM settings
didn't seem to apply. Turns out that I upgraded from a version of
openssh which had pam support on by default to a version that didn't
have pam support unless "UsePAM=yes" was in /etc/ssh/sshd.conf. Since
my old conf file was, well, a conf file, it didn't get updated when I
upgraded.

Granted, I should have been a bit more careful when upgrading, but I'd
also claim that default-off is the WRONG way to ship a package,
especially when the precedent was default-on. This was on an upgrade
from Fedora Core 2 to FC 4.

And, to put your minds at ease, the system was not compromised beyond
the one account. The attacker is still trying to access that account
almost daily, without luck. I've verified all installed packages, and
have been monitoring network traffic from another box with a sniffer.
The attacker wasn't too savvy -- the hack kits installed contained
readme's with lists of systems that they could compromise, most of
which were linux/freebsd/solaris versions that were at least 2 years
old.

I am still experiencing a nearly constant barrage of dictionary attacks
on simple account names (as I have for the past 3 years), sometimes at
a rate of more than one every 5 seconds, but none on any accessible
accounts. I'll likely install some sentry software to automatically
blacklist ips involved in these types of attacks, but am not worried
enough about it right now to, well, worry about it too much.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #12 (permalink)  
Old 01-18-2008, 09:40 AM
Nico Kadel-Garcia
 
Posts: n/a
Default Re: pam, ssh, user account vulnerability


"Lenny G." <alengarbage@yahoo.com> wrote in message
news:1128398175.030150.181660@g43g2000cwa.googlegr oups.com...

> And, to put your minds at ease, the system was not compromised beyond
> the one account. The attacker is still trying to access that account
> almost daily, without luck. I've verified all installed packages, and
> have been monitoring network traffic from another box with a sniffer.
> The attacker wasn't too savvy -- the hack kits installed contained
> readme's with lists of systems that they could compromise, most of
> which were linux/freebsd/solaris versions that were at least 2 years
> old.


Lenny? How did you verify it? Remember that an extremely good rootkit can
replace the MD5 function in your system libraries, and prevent the kernel
from reporting the presence of the rootkit's special kernel modules.



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 12:01 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com