OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] Openssh + security

From: Bruno Cochofel (bruno.cochofelgmail.com)
Date: Wed Dec 14 2005 - 04:25:19 CST


Well I have a problem...
After reconfigured my ssh server based on all your suggestions I've opened
my firewall port so I can connect from anywhere in the Internet (this was
last night).

Today my CPU was around 90% and above and the program that's consuming that
it's X owned by root!!!

This was the same problem that made me ask for ssh options. It's not the
first time this happens...

I'm using publickey auth only, no root logon, and AllowUsers has only one.
My password it's pretty good, chars, numbers, special chars...

Does this mean I've been hacked somehow???

Thnaks,
Bruno