Simple Hack To Protect SSH Against Brute-Force Hacking AttemptsNovember 4th, 2007 All SSH servers on the internet are heavily targeted for brute-force cracking of passwords. Easy passwords can and are often cracked to gain full control over the machine.
Last Week In Perspective: Joel Spolsky, Hani, SSH Hacking, Translator Plugin & Anaconda ThemeSeptember 4th, 2006 Last week was an interesting one as hot debate raged over Joel Spolsky's article on enterprise language, Hani rightly bashed copious logging of open source software and my article on hacking attempts from Caltech topped the list of most read articles. We released Anaconda, a beautiful 3 column WordPress theme and version 3 of Translator Plugin Pro for WordPress.
UK Ministry of Defence Adapts Blackberry.. Is It Safe?September 15th, 2007 UK Ministry of Defence is using secure Blackberry's to allow their staff to communicate on the move. It uses The Blackberry Enterprise Server system which allows lost or stolen smartphones to be remote controlled, shut down, or even wiped clean by IT administrators.
How to start/stop MySQL server on LinuxJanuary 7th, 2005 # To Start MySQL Server
/sbin/service mysqld start
# To Stop MySQL Server
/sbin/service mysqld stop
# To Restart MySQL Server
/sbin/service mysqld restart
And of course there is the brute force way to kill all the processes:
$ for i in `ps -ef |grep mysqld |awk '{print $2}'`; do `kill -9 $i`; done
Thanks to Anthony Eden for the comment (below) to remove the dot in front. A simpler alternative is:
pkill mysqld
This will kill the mysqld process.
Interesting MySpace Hacking TechniqueJune 3rd, 2008 Alicia Keys MySpace page was hacked by inserting a seemingly innocent link with interesting width and height. Let's review the concept.
Short Movie About Computer HackingAugust 25th, 2005 I enjoyed this short informative movie about preventing hacking and protecting your computer from Sunrise, a broadband provider from Switzerland. It talks about firewalls, IP address blocking, spamming, trojans etc.
How To Get Ethical Hacking DegreeJune 21st, 2006 For old-timers (myself included) hacking is not intrinsically unethical, unlike what is potrayed by traditional media. Hacking is a mindset of exploring and solving problems.
Hacking MySpace Mania...September 26th, 2006 Ever since I had written a post on how Samy hacked MySpace, I have been inundated with comments asking me how to hack MySpace. It is obvious that the people asking didn't realize that the actual purpose of the article was not to help hacking MySpace, but to discuss about an intelligent exploit after it was patched.
How to Add an AIM Buddy Icon to TrillianSeptember 8th, 2005 I started using Trillian recently (second time). One of the features of AIM is Buddy Icon.
Answering Joel Spolsky's Questions On Enterprise DevelopmentSeptember 4th, 2006 Joel Spolsky was asked four important questions on enterprise development. Joel didn't offer a clear answer on some of them.
Hacking MySpace Account: Don't Get Duped By False Promises & ScamsOctober 18th, 2007 I recently got two interesting comments from a scammer. The comments are very interesting because it preys on the need of people to snoop around other's MySpace account (or life in general) to dupe them of their own account information.
How To Connect To OpenFire XMPP Server From Gaim / PidginAugust 17th, 2007 I faced quite some problems, to say the least, in configuring Pidgin / Gaim to connect to OpenFire XMPP Server on Fedora Core 6. Here are the detailed steps for a no-brainer configuration of Gaim for OpenFire:
1.
Facebook Hacked!?February 7th, 2009 Facebook has become the most popular social network on the net, even surpassing MySpace. So it is obvious that hackers will now target Facebook more.
How To Block IP Addresses On Linux ServerJuly 12th, 2006 Take a look at your log file (/var/log/secure for Fedora Core 4) and you will discover numerous automated ssh hacking attempts using dictionary attack. So now you have identified the offending addresses.
Google Proxy Hacking - How Your Page Rank Can Be Stolen & Pages Removed from SERPFebruary 23rd, 2008 I recently came across an instance of Google Proxy hacking with one of my clients, which removed his index page and other pages from SERP (Search Engine Ranking & Positioning) and he lost the page ranks (went down to zero). We were asked to protect his site against Google Proxy hacking, a really dangerous technique which can not only cause you to loose page rank but also remove your pages from SERP, all because Google cannot properly identify original pages from duplicates.
August 28th, 2006 at 8:49 am
someone needs DenyHosts on their server
August 28th, 2006 at 9:50 am
I use iptables to block ip addresses. I am thinking for more proactive blocking like DenyHosts to block while an attack is in progress. Thanks for the suggestion.
August 28th, 2006 at 3:36 pm
Be thankful that the attacker was in the US. I have had hundreds of thousands of attacks like what you describe, but originating outside the US. Most of my attacks have been from China, Korea, Japan and Argentina. Complaints to ISPs in those countries are as effective as yelling at my monitor.
August 28th, 2006 at 9:35 pm
That is very true. I find LayeredTech very aggresive in handling such issues, may be even too aggresive. They give you an ultimatum of 6 hours or else face disconnection!
August 29th, 2006 at 12:30 am
hi angsuman,
I know that there are lots of tutorials for password management. can you share what you generally use ? like size, case, etc ?
thank you,
BR,
~A
August 29th, 2006 at 8:55 am
look into recent state match for iptables and forget about ssh brute force attacks…
August 31st, 2006 at 9:49 am
Chris, Thanks for the idea .