Re: Public key authentication and logging

This is a discussion on Re: Public key authentication and logging within the OpenSSH Development forums, part of the Networking and Network Related category; Hi Damien, --- Damien Miller <djm@mindrot.org> a écrit : > Nestor Burma wrote: > > 3/ but if ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-02-2005
Nestor Burma
 
Posts: n/a
Default Re: Public key authentication and logging

Hi Damien,

--- Damien Miller <djm@mindrot.org> a écrit :

> Nestor Burma wrote:
> > 3/ but if a KNOWN user tries to log without a

> known
> > key, we get no message whatsoever.
> >
> > Taking into account all the current brute forcing
> > tools, we feel this is somehow wrong. Of course,

> we
> > get bazillions of failures for unknown users, but
> > unfortunately some tools we saw just hammered

> 'root'
> > and a few, well-known account names. So getting no
> > failure message is bad for us.

>
> "LogLevel verbose" might give you some more details,
> but the
> probability of someone guessing a private key are
> infintisimal.


This is true, but it is not where our problem lies. We
have some particularly painful
blockhead-with-authority reasonning along the line
"privileged accounts are _not_ concerned by all
bruteforcing programs since we see no error messages
in log files".
I know I should just throw him through the nearest
window (17th floor) but hey. Let's find a marginally
more civilized solution :-) So if those reject
messages were in the logfiles, he would see the light.
Maybe.
And is is somehow interesting to know, for example,
what the ratio "root account bruteforcing" to
"non-root account bruteforcing" looks like. Just for
the sake of statistics, flashy graphics and the like.
We'll test "LogLevel verbose", of course.
Thanks,

-- Nb






__________________________________________________ ___________________________
Découvrez le nouveau Yahoo! Mail : 1 Go d'espace de stockage pour vos mails, photos et vidéos !
Créez votre Yahoo! Mail sur http://fr.mail.yahoo.com

_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://www.mindrot.org/mailman/listi...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:24 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0