{"id":618,"date":"2009-03-31T12:50:09","date_gmt":"2009-03-31T16:50:09","guid":{"rendered":"http:\/\/www.schollnick.net\/wordpress\/?p=618"},"modified":"2009-03-31T12:50:09","modified_gmt":"2009-03-31T16:50:09","slug":"security-i-dont-need-to-be-secure-do-i","status":"publish","type":"post","link":"http:\/\/www.schollnick.net\/wordpress\/2009\/03\/security-i-dont-need-to-be-secure-do-i\/","title":{"rendered":"Security?  I don&#8217;t need to be secure&#8230;  Do I?"},"content":{"rendered":"<p>Why does your Information Technology team tell you not to turn on that Web server, or leave SSH turned on when your not using it? \u00c2\u00a0Because they want you to be secure&#8230;<\/p>\n<p>Here&#8217;s a perfect example&#8230;<\/p>\n<address>Mar 30 16:14:06 68 sshd[2933]: Did not receive identification string from 96.10.82.114<br \/>\nMar 30 16:21:57 68 com.apple.SecurityServer[24]: checkpw() returned -2; failed to authenticate user root (uid 0).<br \/>\nMar 30 16:21:57: &#8212; last message repeated 1 time &#8212;<br \/>\nMar 30 16:21:57 68 com.apple.SecurityServer[24]: Failed to authorize right system.login.tty by client \/usr\/sbin\/sshd for authorization created by \/usr\/sbin\/sshd.<br \/>\nMar 30 16:21:57 68 sshd[2957]: <strong>Failed password for root from 96.10.82.114 port 12210 ssh2<\/strong><br \/>\nMar 30 16:21:58 68 sshd[2960]:<strong> Invalid user simoni from 96.10.82.114<\/strong><br \/>\nMar 30 16:21:58 68 com.apple.SecurityServer[24]: getpwnam() failed for user simoni, creating invalid credential<br \/>\nMar 30 16:21:58: &#8212; last message repeated 1 time &#8212;<br \/>\nMar 30 16:21:58 68 com.apple.SecurityServer[24]: Failed to authorize right system.login.tty by client \/usr\/sbin\/sshd for authorization created by \/usr\/sbin\/sshd.<br \/>\nMar 30 16:21:58 68 sshd[2960]: <strong>Failed password for invalid user simoni from 96.10.82.114 port 12418 ssh2<\/strong><br \/>\nMar 30 16:21:59 68 sshd[2962]: <strong>Invalid user dilli from 96.10.82.114<\/strong><br \/>\nMar 30 16:21:59 68 com.apple.SecurityServer[24]: getpwnam() failed for user dilli, creating invalid credential<br \/>\nMar 30 16:21:59: &#8212; last message repeated 1 time &#8212;<br \/>\nMar 30 16:21:59 68 com.apple.SecurityServer[24]: Failed to authorize right system.login.tty by client \/usr\/sbin\/sshd for authorization created by \/usr\/sbin\/sshd.<br \/>\nMar 30 16:21:59 68 sshd[2962]: <strong>Failed password for invalid user dilli from 96.10.82.114 port 12429 ssh2<\/strong><br \/>\nMar 30 16:22:00 68 com.apple.SecurityServer[24]: checkpw() returned -2; failed to authenticate user root (uid 0).<br \/>\nMar 30 16:22:00: &#8212; last message repeated 1 time &#8212;<br \/>\nMar 30 16:22:00 68 com.apple.SecurityServer[24]: Failed to authorize right system.login.tty by client \/usr\/sbin\/sshd for authorization created by \/usr\/sbin\/sshd.<br \/>\nMar 30 16:22:00 68 sshd[2964]: Failed password for root from 96.10.82.114 port 12449 ssh2<br \/>\nMar 30 16:22:01 68 sshd[2967]: <strong>Invalid user ale from 96.10.82.114<\/strong><br \/>\nMar 30 16:22:01 68 com.apple.SecurityServer[24]: getpwnam() failed for user ale, creating invalid credential<\/address>\n<address>\n<\/address>\n<p>This user used SSH on the mac for a few days, and then forgot to turn it off.\u00c2\u00a0 We don&#8217;t know how long these script kiddies were attacking the system, attempting to guess the password&#8230;\u00c2\u00a0 But between the reasonably strong password, and LaunchD automatically throttling back SSHD launches, they never cracked the system.\u00c2\u00a0 But that was partially due to the fact that the user happened to see the attempts in the System Log&#8230;<\/p>\n<p>Please review your System Preferences&#8217;s Sharing configuration, and if you are not running a web site turn off &#8220;Web Sharing&#8221;.\u00c2\u00a0 If you are not using SSH, then please turn off &#8220;Remote Login&#8221;. And most important of all, if you are not allowing Windows users to login to your system, make sure File Sharing is turned off.<\/p>\n<p>If you wish to File Share with the other Macintosh systems, and exclude the Windows users&#8230; Choose File Sharing.\u00c2\u00a0 Click Options, and make sure &#8220;Share Files and Folder using SMB&#8221; is turned off.\u00c2\u00a0 And make sure that &#8220;Share Files &amp; Folders using FTP&#8221; is turned off.\u00c2\u00a0 Unless your running an FTP server, there is no reason for that option to be on (in most cases).<\/p>\n<p>If you are not sure about any of the other settings, ask your local IT representative for help.\u00c2\u00a0 I&#8217;m sure that they would rather take 5 minutes to review security settings, then spend hours cleaning up your system from a script kiddie attack.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Why does your Information Technology team tell you not to turn on that Web server, or leave SSH turned on when your not using it? \u00c2\u00a0Because they want you to be secure&#8230; Here&#8217;s a perfect example&#8230; Mar 30 16:14:06 68 sshd[2933]: Did not receive identification string from 96.10.82.114 Mar 30 16:21:57 68 com.apple.SecurityServer[24]: checkpw() returned <a class=\"read-more\" href=\"http:\/\/www.schollnick.net\/wordpress\/2009\/03\/security-i-dont-need-to-be-secure-do-i\/\">[&hellip;]<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0},"categories":[12,5,25,11],"tags":[78,1838,83],"_links":{"self":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/posts\/618"}],"collection":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/comments?post=618"}],"version-history":[{"count":0,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/posts\/618\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/media?parent=618"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/categories?post=618"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.schollnick.net\/wordpress\/wp-json\/wp\/v2\/tags?post=618"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- WP Super Cache is installed but broken. The constant WPCACHEHOME must be set in the file wp-config.php and point at the WP Super Cache plugin directory. -->