Blogs Classifieds Downloads FlashChat Gallery Googlemap Invite Friends Links Projects Reviews Wiki
 


Our Sponsors
Want to advertise?  


Reply
 
LinkBack Thread Tools
  #1  
Old February 2nd, 2010
Madhu.A's Avatar
Madhu.A Offline
Junior Member
 
Join Date: September 2008
Posts: 20
Securing AIX server

Hi All,

Can any one let me know the detailed steps that can be taken to secure server when it is found some one(not an user in system) is trying to login/hack into server.

I have only the below details.

UNKNOWN_ - ssh Jan 18 09:49 ?
UNKNOWN_ - ssh Jan 27 15:32 ?
UNKNOWN_ - ssh Jan 27 15:32 ?
UNKNOWN_ - ssh Jan 27 15:32 ?
UNKNOWN_ - ssh Jan 27 15:32 ?
UNKNOWN_ - ssh Jan 29 13:20 ?

Regards
Madhu
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #2  
Old February 2nd, 2010
dthacker's Avatar
dthacker Offline
Cat Herder and Penguin Wrangler
 
Join Date: June 2006
Location: Omaha, Nebraska USA
Posts: 99
Send a message via Yahoo to dthacker
Re: Securing AIX server

Madhu,
What log are you seeing that information in?

Dave
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #3  
Old February 3rd, 2010
Madhu.A's Avatar
Madhu.A Offline
Junior Member
 
Join Date: September 2008
Posts: 20
Re: Securing AIX server

hi Dave,

This info was found from /etc/security/failedlogin.

Madhu
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #4  
Old February 3rd, 2010
duke900ssd's Avatar
duke900ssd Offline
Senior Member
 
Join Date: March 2007
Posts: 368
Re: Securing AIX server

Eg.
UNKNOWN_ - ssh Jan 18 09:49 ?

The UNKNOWN means they used an unknown user ID to try and login, typed an unknown username in.

The ? at the end means the system was not able to resolve the hostname of the system the user was trying to login from.

So your system was secure, they did not know (or use) a valid login name.

It is probably someone trying to get into the wrong box using a wrong hostname or IP address.

How do you think you could make it more secure?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #5  
Old February 4th, 2010
ross.mather's Avatar
ross.mather Offline
Senior Member
 
Join Date: January 2007
Location: Nomadic in the UK
Posts: 608
Re: Securing AIX server

Duke is right - your server has denied access to someone who didn't use a valid user id.

If you want to strengthen your password rules to make hacing more difficult then take a look at aixpert. Recent versions of AIX have this and allows you to set a number of security settings on an AIX Server.

These settings include insecure services telnet andftp for example and the password rules.

As with any change on the server they may have unintended side effects (such as if people really use ftp) so make sure you understand what it will do before you apply the settings.
__________________
Ross Mather, IBM AIX IT Specialist.
That said anything I say here is my own opinion and not anything that you can ever hold against IBM.
Ohhh and don't forget that I make mistakes too....
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #6  
Old February 4th, 2010
Madhu.A's Avatar
Madhu.A Offline
Junior Member
 
Join Date: September 2008
Posts: 20
Re: Securing AIX server

how about enabling the syslog in the server, so that it may capture more info and better then the /etc/security/failedlogin ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #7  
Old February 4th, 2010
seth's Avatar
seth Offline
Senior Member
 
Join Date: June 2008
Posts: 297
Re: Securing AIX server

How much of these "UNKNOWN_ - ssh Jan 18 09:49 ?" entries do you have? If there are only 6 someone has got the wrong ip/name to login. If there are hundereds or thousands of them then you can call it a attack then I would tune settings like logindelay, logindisable, logininterval, loginreenable and logintimes in the etc/security/login.cfg file.
With the right settings there the attacker will stop soon an go for another target.

Cheers seth
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #8  
Old February 4th, 2010
Madhu.A's Avatar
Madhu.A Offline
Junior Member
 
Join Date: September 2008
Posts: 20
Re: Securing AIX server

There are more then 90 attempts has been made!! ..
but not all in single day and still I need to work on this issue....

So any suggestions how to proceed further ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #9  
Old February 4th, 2010
seth's Avatar
seth Offline
Senior Member
 
Join Date: June 2008
Posts: 297
Re: Securing AIX server

As I already said:

Quote:
Originally Posted by seth View Post
... I would tune settings like logindelay, logindisable, logininterval, loginreenable and logintimes in the etc/security/login.cfg file.
...
look at the file there are the mentioned parameters explained. We wont do that for you ...

Cheers seth
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
  #10  
Old February 4th, 2010
Madhu.A's Avatar
Madhu.A Offline
Junior Member
 
Join Date: September 2008
Posts: 20
Re: Securing AIX server

sure ... let me try that and i'll update u guys ....
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Spurl this Post!Reddit! Wong this Post!
Reply With Quote
Reply

Bookmarks

Tags
aix, securing, server

These are the 100 most searched terms
Search Cloud
0042-001 0042-001 nim 0042-008 nimsh: request denied 0513-001 the system resource controller daemon is not active 0513-001 the system resource controller daemon is not active. 0514-061 0514-061 cannot find a child device 0514-061 cannot find a child device. 0516-787 0516-787 extendlv 0516-787 extendlv: maximum allocation for logical volume 110000ac 3074feb7 aa00e1f3 aio aix aix aio aix freeware aix memory usage aix rsync aixif_arp_dup_addr b150f22a b181f22a b181fb53 ba010004 bfe4c025 c1001020 d133c002 dacnone dcb47997 fcp_array_err6 fget_config gnu tar aix gtar aix hmc root password hmc vmware ibm p6 520 libpopt.a migratelv navisphere agent nim server pseriestech ptype and account type do not match rshd: 0826-813 permission is denied rshd: 0826-813 permission is denied. rsync aix sc_disk_err4 scan_error_chrp vio server vmware hmc websm ... powered by Simple Search Cloud


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.2.0
Powered by vbWiki Pro 1.3 RC5. Copyright ©2006-2007, NuHit, LLC

vBulletin Skin developed by: vBStyles.com


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82