Welcome to Help4Web.co.uk - Web Design Help, Html Tutorial, Php, Asp , SQL help and CCNA, MCSE definitions!
Google
Webkpop-web.com

     Main Menu

· Home
· Free Downloads
· Computing FAQ
· Contact Us
· Free Software Downloads
· Tech Forum
· Technology News
· Web Design Help
· Web Links
· Your Online Account
· Your PM



     Web Browser


     Website Links
Supermediastore! #1 in Computer media & Accessory

White Papers IT
Learn Korean
Chinese Pop Music
Advertise Kpop
Korean Pop Site Map
Web Design
Pop Music
Chinese Girls
HK Pop Korean Music
Lee Hyori
Hyori
Boa Park Ji Yoon
Baby Vox YG Family
Jeon Ji Hyun
1 Tym Ha Ji Won
Shyne Rain Bi
Shin Mina SM Town
Fly to the Sky
Korean Girls and Models
Nicholas Tse
161 Clan
보아
Edison Chen
Sung Hi Lee
Shinhwa
Andy Lau Jay Chou
White Papers
Case Study SES
Kelly Chen
Liu Yi Fei Sammi Cheng
Jordan Chan Music
Computer Jobs IT

Computer Help Forum and Programming Advice :: View topic - Can I limit ssh logins to one hostname?
 Forum FAQForum FAQ   SearchSearch   UsergroupsUsergroups   ProfileProfile   Log inLog in 

Can I limit ssh logins to one hostname?

 
Post new topic   Reply to topic    Computer Help Forum and Programming Advice Forum Index -> Information Security
View previous topic :: View next topic  
Author Message
tofuman
Freshman
Freshman


Joined: Oct 18, 2005
Posts: 8

PostPosted: Mon Jan 23, 2006 10:00 pm    Post subject: Can I limit ssh logins to one hostname? Reply with quote

Hi,

I am running a server, and since it contains a number of websites, it uses a number of hostnames, including its IP address, of course.

I've been receiving a number of login attempts to username: root, among others, and one of the ways I thought of combatting this was to limit all ssh requests to a single hostname that is not used anywhere else (such as sshlogin.domain.tld)

Is there a way to restrict all ssh requests to a specific hostname?
Back to top
View user's profile Send private message
londis
Web Design Newbie
Web Design Newbie


Joined: Jul 18, 2004
Posts: 47

PostPosted: Mon Jan 23, 2006 10:02 pm    Post subject: Reply with quote

You can have sshd listen to a particular IP and port. Take a look at the sshd_config man page and look for ListenAddress option. It looks like you can do something like:
Code:
ListenAddress 123.456.789.012:22


to listen on a particular IP address at the default port.

But realize that you're only moving the problem. People will still try to probe the ssh port regardless of the host name. Mostly the host name is irrelevant - they only go after the IP anyway.

If you can't restrict the IP's that are allowed to access the machine via ssh (i.e. only allow a few machines to even see that the host has an open ssh port using iptables) then make sure you keep up with patches, don't allow direct root login, and have good passwords for any account that you do allow logins to.
Back to top
View user's profile Send private message
trekkie
Web Design Newbie
Web Design Newbie


Joined: Oct 18, 2005
Posts: 15

PostPosted: Mon Jan 23, 2006 10:03 pm    Post subject: Reply with quote

Okay, thanks.

I was thinking you could somehow configure it so SSH will not allow connections to simply its IP, but a specific hostname.

I guess I'll be using keygens then.
Back to top
View user's profile Send private message
Display posts from previous:   
Post new topic   Reply to topic    Computer Help Forum and Programming Advice Forum Index -> Information Security All times are GMT + 10 Hours
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum







Learn Chinese | Learn cantonese | Learn Mandarin | Grace Park | Party Organisers | Kaila yu | Phone Card | Twins | Chinese Society | Loans UK | BokuMaro | CV Help Book | Chinese Wife | Korean Singles | British Born Chinese | Bae Yong Jun | Speak Korean | Chinese Models | Music | Information Security Management | Maritime Greenwich Campus | Covering Letters Help | Chinese Music | Jang Nara | SES | YG Family | Learn Korean | Firewall Definition | Server Definition | Wireless Network Definition | E-Commerce Definition | Sales Leads | Application Firewall | CCNA definitions | Research Papers | Webcast | CV Help

Author KPop Music :- Jon Bock ( Chinese Pop Music Learn Korean )
Produced by Kpop-Web Design Associates, all rights not reserved.
Internet Marketing and Search Engine Optimisation Software Defined Radio