3 ms·
Keep in mind though that while securing SSH is a good approach, SSH itself is very unlikely to be the route of compromise unless an extremely insecure account w
by ultramancool 10y ago
Keep in mind though that while securing SSH is a good approach, SSH itself is very unlikely to be the route of compromise unless an extremely insecure account were present with weak password auth.
It's far more likely that the attacker got legit credentials via another means, web application vulnerability, social engineering or malware attack on company machines, etc. I'd look at the less common applications you run, particularly anything that doesn't particularly look like it was designed to run facing the internet. For example, the elasticsearch guys decided that it would be a great idea to allow anyone who can access it to run java code on the server at one point...
- laumars 10y agoIndeed, however some of my points still secure against that: 1. firewalling to only the sysadmin's IPs, 2. SSH keys + disabling password logins 6. and disabling SSH on internet facing IPs altogether (if possible).
- tkinom 10y agoI was wondering..... If someone in the datacenter can image the VM and mount it some place in their own machine, reset the ssh rsa key, etc. Is it good enough to "produce" the proof of the hack? If so, than no amount of "clean up" can fix the issue, right?