Get the App
SLTechnology News&Howtos  ›  Servers  › 

Example Analysis of SSH cracking Prevention in linux Server

Shulou Source: shulou.com Published: 2022-06-01 18:23:00 10月03日 Update

This article is to share with you the content of a sample analysis of SSH cracking prevention in linux servers. The editor thinks it is very practical, so share it with you as a reference and follow the editor to have a look.

1. Linux server forbids IP from logging in to my server through SSH by configuring / etc/hosts.deny

Vim / etc/hosts.deny

2. Instead of using the default port 22 of the SSH service, reset a new port, preferably with a new port number greater than 1024

First, log in to the Aliyun console and open a new port on your server.

Then, modify the configuration file of SSH on the server, add a line of Port 1618 to the file, and save exit (: wq)

Vim / etc/ssh/sshd_config

The SSH service needs to be restarted after each change to the ssh service configuration

Service sshd restart

3. Do not give the other party a chance to crack it violently. Delete a common user such as admin, and the other party cannot guess the user name, so the password cannot be violently cracked (userdel-r means to delete completely without retaining the user's file information)

Userdel-r admin

4. Root users are prohibited from logging in through SSH, because the default super user name of the server is root, and the other party will have the opportunity to violently crack the password with the user name of root. If the password is cracked successfully, it can cause too much damage, especially in the production environment, so you can do this. Log in to SSH with other users, and if necessary, use su-switch back to the root user.

Vim / etc/ssh/sshd_config

Change the line PermitRootLogin yes to PermitRootLogin no

5. The password of the user who logs in to SSH is as complex as possible.

Thank you for reading! This is the end of this article on "sample Analysis of SSH cracking Prevention in linux Server". I hope the above content can be of some help to you, so that you can learn more knowledge. if you think the article is good, you can share it for more people to see!

Tags: Services users servers logins counterparties passwords files violence ports configuration examples analysis one line content more opportunities user names articles good complex Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Shulou Technology OPPO Reno Microsoft Shulou Information macOS