4 ms·
Another thing that would be extremely helpful is improved logging. If the ssh-agent logged the entity that was attempting to hijack the connection it would be p
by staticassertion 5y ago
Another thing that would be extremely helpful is improved logging. If the ssh-agent logged the entity that was attempting to hijack the connection it would be pretty easy to write detection logic for weird shit.
We'll probably publish about this in the next few months, my colleague added some logging and we wrote ~10 detections on the process tree + IPC signatures. It makes the entire attack extremely dangerous for an attacker.
- laurent92 5y agoPort 22 shouldn’t be accessible from the internet, in addition. Some people say it shouldn’t be port 22, but we dip into security by obscurity, while making it annoying for you to use.
- staticassertion 5y agoThat doesn't really have to do with the ssh-agent or key forwarding though.
- mjochim 5y agoChoosing some other port than 22 is not a measure to make things more secure; as you say, it would be security by obscurity. But it massively unclogs audit logs if, for some reason, SSH is exposed to the internet.
- bch 5y ago> Choosing some other port than 22 is not a measure to make things more secure; as you say, it would be security by obscurity. There’s nothing wrong with security through obscurity as long as it’s not your only security. Defence in depth, including obscurity if it suits you.
- mrweasel 5y agoWhere I'd advise against moving the SSH port, and other ports for that matter, is in the cases where a larger number of people might need access on and off. We had to deal with a client who believe that fail2ban and moving the SSH port was the two single greatest inventions of all time. As such there's nothing wrong with either of those to solution, except if you have a contractor handling alerts during the night. Even with pretty good documentation, people will get this wrong, and they will accidentally lock them selfs out and not they can't do anything to fix your broken system. I'm much more in favor of keeping everything "default" and locking down the network. You don't need to worry about ports and log spamming, if the only hosts that are even able to reach your bastion host is the two IPs you explicitly allowed in the firewall.
- Firehawke 5y agoExactly this. As an additional layer of obfuscation, it's useful-- it just should never be your only defense. People take the "never do security through obscurity" thing a little too literally.
- mjochim 5y agoGood point. At the very least, it buys you time while attackers try to deobfuscate. How valuable that is is left for everyoneto judge; especially considering what a sibling says about locking yourself out - basically you and your team might also have to deobfuscate and thus lose time.
- deleted 5y ago[deleted]