Ruminations on an SSH attack

Brian Chabot brian at datasquire.net
Sun Dec 18 20:58:00 EST 2005


Bill McGonigle wrote:

> I sleep better at night knowing my servers have these lines in them:
>
> Protocol 2
> PermitRootLogin no
> IgnoreRhosts yes
> PasswordAuthentication no
> AllowUsers ...


I like to add in:

MaxAuthTries 6
UsePrivilegeSeparation yes

AllowUsers can be a pain if your user bas changes..


Brian



More information about the gnhlug-discuss mailing list