FediScanner

#ssh

← Back

Mein kleiner #GoToSocial #Debian 13 Server wird momentan aus China von einer massiven Rotte #SSH Login #Bots zugemüllt. Es sind ganze /24er Netze. #Fail2Ban wäre für den kleinen Server Overkill und würde vermutlich mehr schaden als nützen. Also etwas kleines handliches. Ein Script, welches das Journal nach Loginversuchen abgrast und die Blöcke für 24h erdet. Mal sehen, ob ich die Zeit noch verlängern werde. Die Lümmels haben sogar den unüblichen Port gefunden. Wenn ich ihn verschiebe, dauert es nicht lange, bis sie dort aufschlagen. Und so habe ich #nftables und ein kleines #bash Script eingesetzt, um das Treiben zu bremsen. Es funktioniert gut. Momentan sind direkt 5 verschiedene /24 Netze blockiert.
notes.j62.de/?file=Gemini-SSH-

Show Original PostReport

In ssh_config, why does VerifyHostKeyDNS default to "no"? Combined with the default StrictHostKeyChecking set to "ask", this means that manual host key verification by the user is preferred to automatic host key checking via dns. I suspect 90% of "unrecognised host key" prompts are accepted blindly and never manually validated, which seems like lower security than automatic host key validation. Is there a security risk to SSHFP record checking?

Show Original PostReport

Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages

A supply chain attack compromised multiple @redhat-cloud-services npm packages, executing malicious payloads automatically during installation via preinstall hooks. The attack uses AES-GCM encrypted payloads and obfuscated JavaScript loaders to harvest GitHub Actions secrets, npm tokens, cloud credentials (AWS, Azure, GCP), Kubernetes and Vault material, SSH keys, Git credentials, and cryptocurrency wallet files. The payload can daemonize on developer workstations, includes Russian-locale avoidance mechanisms, and exfiltrates stolen data through encrypted HTTPS channels with GitHub API fallback mechanisms. The campaign employs tactics similar to the publicly released Shai-Hulud toolkit, though attribution remains unclear due to the availability of open-source attack tooling.

Pulse ID: 6a1dde0e4e662ca1f8b4b0b2
Pulse Link: otx.alienvault.com/pulse/6a1dd
Pulse Author: AlienVault
Created: 2026-06-01 19:31:26

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#AWS #Azure #Cloud #CyberSecurity #GitHub #HTTP #HTTPS #ICS #InfoSec #Java #JavaScript #NPM #OTX #OpenThreatExchange #RAT #RCE #Russia #SMS #SSH #SupplyChain #bot #cryptocurrency #AlienVault

Show Original PostReport

@leftover

Ich bleibe erstmal bei #Fail2Ban – die Einrichtung ist mir dann doch etwas zu kompliziert. Wenn ich irgendwann Zeit habe, werde ich den öffentlichen #SSH-Zugang abschalten und den Server nur noch über einen WireGuard-Tunnel erreichbar machen. Das sollte völlig ausreichen.

Trotzdem danke für die Infos.

Show Original PostReport