You are not logged in.

#1 2017-08-01 11:13:41

mouseman
Member
From: Outta nowhere
Registered: 2014-04-04
Posts: 291

[solved]sshd not using libwrap

tl;dr: libwrap support has been dropped from sshd.
-----------
So I've been trying to get sshd to use /etc/hosts.deny but I can't get it to work. As far as I'm aware there are 3 requirements: sshd needs to be compiled with tcp_wrapper support, a valid /etc/hosts.deny needs to exist, sshd needs to be configured to listen on an IP address and not 0.0.0.0.

I can check off the hosts.deny and sshd config, but when I run:

# ldd /usr/sbin/sshd | grep libwrap

I get no return; I have installed libwrap and lib32-libwrap, restarted sshd to be sure but it's still not working.

Am I correct in now concluding that sshd is not compiled with tcp wrapper support? Because I thought that was default (thought I read that somewhere).

Any ideas?

Thanks!

Last edited by mouseman (2017-08-01 11:43:11)

Offline

#2 2017-08-01 11:28:05

WorMzy
Forum Moderator
From: Scotland
Registered: 2010-06-16
Posts: 11,845
Website

Re: [solved]sshd not using libwrap

libwrap support was dropped from openssh a while ago: http://marc.info/?l=openssh-unix-dev&m= … 608284&w=2

if you want to secure your server I suggest you look at https://wiki.archlinux.org/index.php/Security#SSH


Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD

Making lemonade from lemons since 2015.

Offline

#3 2017-08-01 11:42:26

mouseman
Member
From: Outta nowhere
Registered: 2014-04-04
Posts: 291

Re: [solved]sshd not using libwrap

Thanks for the info. With all the searching I've done it's crazy I haven't run into that myself. Been at it for a few days already.

I've gone through the wiki list already and I have a pretty secure setup already using only ssh keys, 2FA using Google Authenticator and root disallowed. My logs are getting flooded however with brute force attempts so I wanted to use denyhosts script to fill up /etc/hosts.deny.

Instead, I'll look into iptables and auto banning using that. Maybe fail2ban ...

Thanks!

Offline

Board footer

Powered by FluxBB