#scary #ai #video #rewardhacking when #ai finds unwanted ways to score higher, whoever grants #AI such #powers like calling other tools like #ssh or full #filesystem #access is indeed acting #irresponsible #openclaw
#ssh
Mein kleiner #GoToSocial #Debian 13 Server wird momentan aus China von einer massiven Rotte #SSH Login #Bots zugemüllt. Es sind ganze /24er Netze. #Fail2Ban wäre für den kleinen Server Overkill und würde vermutlich mehr schaden als nützen. Also etwas kleines handliches. Ein Script, welches das Journal nach Loginversuchen abgrast und die Blöcke für 24h erdet. Mal sehen, ob ich die Zeit noch verlängern werde. Die Lümmels haben sogar den unüblichen Port gefunden. Wenn ich ihn verschiebe, dauert es nicht lange, bis sie dort aufschlagen. Und so habe ich #nftables und ein kleines #bash Script eingesetzt, um das Treiben zu bremsen. Es funktioniert gut. Momentan sind direkt 5 verschiedene /24 Netze blockiert.
https://notes.j62.de/?file=Gemini-SSH-Schutz+mit+nftables+und+Scripts.md
Production GUI recommendation for Ubuntu Server 24.04 – XRDP issues causing application downtime #server #ssh #xfce #remotedesktop #production
Production GUI Recommendation for Ubuntu 24.04 Server – XRDP Issues Causing Application Downtime #server #ssh #xfce #remotedesktop #production
Curso Gratuito de Linux Debian: Aprenda Administração de Servidores na Prática
https://guiadeti.com.br/curso-gratuito-linux-debian/
#administracaodesistemas #aws #cloudcomputing #cursoonline #debian #devops #infraestrutura #linux #linuxdebian #linuxserver #servidores #softwarelivre #ssh #sysadmin #tecnologia
https://guiadeti.com.br/curso-gratuito-linux-debian/?fsp_sid=1034
It depends upon your preference
Sometimes I want to see everything in the most beautiful rainbow colors that exist
I then invoke lolcat(6) in my SSH login string.
Then everything looks gorgeous!
In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?
Ale ze mi sie #ssh w #jellyfin tak samo z siebie po prostu zepsuje, to nie przypuszczalem.
SSH! this just happened:
Jun 2 18:01:49 skapet sshd-session[53576]: Failed password for invalid user root/admin from 161.97.110.92 port 46558 ssh2
#ssh #passwordgropers #sshgropers #passwordguessers #cybercrime #bots #botnets
Just know OpenSSH’s `ControlMaster` feature exists
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
A supply chain attack compromised multiple @redhat-cloud-services npm packages, executing malicious payloads automatically during installation via preinstall hooks. The attack uses AES-GCM encrypted payloads and obfuscated JavaScript loaders to harvest GitHub Actions secrets, npm tokens, cloud credentials (AWS, Azure, GCP), Kubernetes and Vault material, SSH keys, Git credentials, and cryptocurrency wallet files. The payload can daemonize on developer workstations, includes Russian-locale avoidance mechanisms, and exfiltrates stolen data through encrypted HTTPS channels with GitHub API fallback mechanisms. The campaign employs tactics similar to the publicly released Shai-Hulud toolkit, though attribution remains unclear due to the availability of open-source attack tooling.
Pulse ID: 6a1dde0e4e662ca1f8b4b0b2
Pulse Link: https://otx.alienvault.com/pulse/6a1dde0e4e662ca1f8b4b0b2
Pulse Author: AlienVault
Created: 2026-06-01 19:31:26
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#AWS #Azure #Cloud #CyberSecurity #GitHub #HTTP #HTTPS #ICS #InfoSec #Java #JavaScript #NPM #OTX #OpenThreatExchange #RAT #RCE #Russia #SMS #SSH #SupplyChain #bot #cryptocurrency #AlienVault
Ich bleibe erstmal bei #Fail2Ban – die Einrichtung ist mir dann doch etwas zu kompliziert. Wenn ich irgendwann Zeit habe, werde ich den öffentlichen #SSH-Zugang abschalten und den Server nur noch über einen WireGuard-Tunnel erreichbar machen. Das sollte völlig ausreichen.
Trotzdem danke für die Infos.