PHWinfo banniere

Titres
PORTAIL ANNUAIRE ARTICLES COMPARATEUR HÉBERGEURS DEVIS FORUMS RÉDUCTEUR D'URL
Précédent   PHWinfo > Forums Hébergement > Forum Serveur - Sécurité et techniques > comp.security.ssh > Have I been hacked?
S'inscrire FAQ Membres Recherche Messages du jour Marquer les forums comme lus
comp.security.ssh SSH secure remote login and tunneling tools.

Have I been hacked?

Réponse
 
LinkBack Outils de la discussion
Vieux 06/08/2007, 19h48   #1
hkg166@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Have I been hacked?

I was using RSA keys authentication and it was working fine. I just
noticed someone logged onto my computer other than me. I checked, and
it seems like sshd is now not checking the keys. I have not changed my
sshd_config in some time. Is there something that stops it from
working lately?

Thanks.. (I am running OS X 10.4)


# Authentication:

#LoginGraceTime 120
PermitRootLogin no
#StrictModes yes

RSAAuthentication yes
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys

# rhosts authentication should not be used
#RhostsAuthentication no
# Don't read the user's ~/.rhosts and ~/.shosts files
#IgnoreRhosts yes

  Réponse avec citation
Vieux 06/08/2007, 21h50   #2
Steve Sentoff
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Have I been hacked?

hkg166@gmail.com wrote:
> I was using RSA keys authentication and it was working fine. I just
> noticed someone logged onto my computer other than me. I checked, and
> it seems like sshd is now not checking the keys. I have not changed my
> sshd_config in some time. Is there something that stops it from
> working lately?
>
> Thanks.. (I am running OS X 10.4)
>
>
> # Authentication:
>
> #LoginGraceTime 120
> PermitRootLogin no
> #StrictModes yes
>
> RSAAuthentication yes
> PubkeyAuthentication yes
> AuthorizedKeysFile .ssh/authorized_keys
>
> # rhosts authentication should not be used
> #RhostsAuthentication no
> # Don't read the user's ~/.rhosts and ~/.shosts files
> #IgnoreRhosts yes
>


If, by "not checking the keys", you mean sshd is allowing users to
authenticate with passwords, you need to check the
PasswordAuthentication option in sshd_config.

If you mean that users can authenticate with a bogus RSA key, you have a
real problem.
--
Steve
  Réponse avec citation
Vieux 07/08/2007, 05h53   #3
Russell Wood
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Have I been hacked?

On 2007-08-06, hkg166@gmail.com <hkg166@gmail.com> wrote:
> I was using RSA keys authentication and it was working fine. I just
> noticed someone logged onto my computer other than me.


If you're the only person who is authorised to be logged on, then yes.

--
Russell Wood
<http://www.dynode.net/~rjw/>
  Réponse avec citation
Vieux 15/08/2007, 16h01   #4
purpmint008@gmail.com
Aucun Avatar
 
Messages: n/a
Hébergeur:
Par défaut Re: Have I been hacked?

X-No-Archive: Yes

It should be checking the keys but make sure that password
authentication is turned off.
Which version of SSH are you using?
Make sure you are only using SSH2 for maximum security
"RSAAuthentication yes" only applies to SSH1

>From OpenSSH (sshd_config):

http://www.openbsd.org/cgi-bin/man.c...ry=sshd_config
RSAAuthentication: Specifies whether pure RSA authentication is
allowed. The default is ``yes''. This option applies to protocol
version 1 only.

  Réponse avec citation
Réponse


Outils de la discussion

Règles de messages
Vous ne pouvez pas créer de nouvelles discussions
Vous ne pouvez pas envoyer des réponses
Vous ne pouvez pas envoyer des pièces jointes
Vous ne pouvez pas modifier vos messages

Les balises BB sont activées : oui
Les smileys sont activés : oui
La balise [IMG] est activée : oui
Le code HTML peut être employé : non
Trackbacks are oui
Pingbacks are oui
Refbacks are oui


Fuseau horaire GMT +1. Il est actuellement 05h07.


Édité par : vBulletin® version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0 RC5 Tous droits réservés.
Version française #16 par l'association vBulletin francophone
PHWinfo est un site Éducation Sans Frontières ©2000-2008
Ad Management by RedTyger
©Tous droits réservés par les parties respectives
Page generated in 0,09246 seconds with 12 queries