Networking Forums

Networking Forums > Computer Networking > Linux Networking > Intrusion or not

Reply
Thread Tools Display Modes

Intrusion or not

 
 
Nils Gorges
Guest
Posts: n/a

 
      09-14-2004, 06:16 PM
Hello NG,

i will ask you for your opinion for the follow situation since i cannot
judge it myself.

While connecting by using ssh to my server the server welcomed me with
this message:

@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
@ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!

I definitly changed nothing at the server and client configuration. I
didn't change any host key and i never got that message before.

All logs and status informations seems to be ok, the only thing is,
message log shows, that the server was restarted 2 times last night.
First time at 2 a.m., second time at 6 a.m and it is located in a
computer center with USV.

So what do you think? Does this indicate a successful intrusion or is it
vice versa and the host key warning comes because the server restarted
for some reasons?

Hope you can help.

Thank you

Nils

 
Reply With Quote
 
 
 
 
Michael Heiming
Guest
Posts: n/a

 
      09-14-2004, 10:04 PM
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
NotDashEscaped: You need GnuPG to verify this message

[ Followup-To comp.security.ssh ]

In comp.os.linux.networking Nils Gorges <(E-Mail Removed)> suggested:
> Hello NG,


> i will ask you for your opinion for the follow situation since i cannot
> judge it myself.


> While connecting by using ssh to my server the server welcomed me with
> this message:


> @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
> @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
> IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> Someone could be eavesdropping on you right now (man-in-the-middle attack)!


That's your ssh client that makes the message.

> I definitly changed nothing at the server and client configuration. I
> didn't change any host key and i never got that message before.


> All logs and status informations seems to be ok, the only thing is,
> message log shows, that the server was restarted 2 times last night.
> First time at 2 a.m., second time at 6 a.m and it is located in a
> computer center with USV.


Investigate why, logrotate from cron might be a reason, but not
twice.

> So what do you think? Does this indicate a successful intrusion or is it
> vice versa and the host key warning comes because the server restarted
> for some reasons?


The server key won't change if the server is restarted, never.
Double check the version of sshd (OpenSSH_3.9p1 is the latest),
and any other package version for known security problems. Sounds
suspicious, something has changed, your ~/.ssh/known_hosts, your
system wide known_hosts if any or the server key has been
exchanged.

--
Michael Heiming (GPG-Key ID: 0xEDD27B94)
mail: echo (E-Mail Removed) | perl -pe 'y/a-z/n-za-m/'
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBR2r6AkPEju3Se5QRAh6/AJ41vEi3QzOOjHG4r4PNkoQyOYqSGACfa1QO
Phr545WtQEPl7vrbolsuEDI=
=nBUk
-----END PGP SIGNATURE-----
 
Reply With Quote
 
Jose Maria Lopez Hernandez
Guest
Posts: n/a

 
      09-15-2004, 03:28 PM
Nils Gorges wrote:
> Hello NG,
>
> i will ask you for your opinion for the follow situation since i cannot
> judge it myself.
>
> While connecting by using ssh to my server the server welcomed me with
> this message:
>
> @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
> @ WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ @@@@@@@@@
> IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> Someone could be eavesdropping on you right now (man-in-the-middle attack)!


This happens if you change the keys in some of the end of
the connection. It shouldn't happen if you haven't changed
anything.

--

Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
(E-Mail Removed)
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com
ESPAÑA

The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
-- Jack Kerouac, "On the Road"
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Intrusion Detection using snort Ivan Linux Networking 1 11-23-2007 11:27 AM
network intrusion Gary Wessle Network Routers 0 05-12-2007 03:44 PM
Intrusion possible? Tardus_merula Wireless Internet 17 10-02-2005 08:16 AM
Intrusion detection suggestions Madhusudan Singh Linux Networking 2 08-13-2004 06:39 PM
Intrusion Alerts Andy R Home Networking 0 01-06-2004 01:54 PM



1 2 3 4 5 6 7 8 9 10 11