{"id":235,"date":"2010-06-11T10:00:20","date_gmt":"2010-06-11T15:00:20","guid":{"rendered":"http:\/\/hackarandas.com\/blog\/?p=235"},"modified":"2010-06-11T00:47:37","modified_gmt":"2010-06-11T05:47:37","slug":"ssh-hacking-and-good-practices","status":"publish","type":"post","link":"https:\/\/hackarandas.com\/blog\/2010\/06\/11\/ssh-hacking-and-good-practices\/","title":{"rendered":"SSH Hacking and Good Practices"},"content":{"rendered":"<p><a href=\"http:\/\/hackarandas.com\/blog\/wp-content\/uploads\/2010\/06\/ssh.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/hackarandas.com\/blog\/wp-content\/uploads\/2010\/06\/ssh.jpg\" alt=\"\" title=\"ssh\" width=\"132\" height=\"208\" style=\"margin: 10px 10px 0pt 0pt; float: left;\" \/><\/a>  I got to confess that I am a big podcast fan and one I am fond of is <a href=\"http:\/\/www.pauldotcom.com\/security-weekly\/\">PaulDotCom &#8211; Security Weekly<\/a> (I also hear it while I am jogging) So when I read in the blog the Mark Baggett&#8217;s post: <a href=\"http:\/\/pauldotcom.com\/2010\/04\/capturing-ssh-v1-v2-credential.html\">Capturing SSH V1 &#038; V2 Credentials with a MitM ssh honeypot<\/a> I just feel like &#8220;I have to try it&#8221;. So I did and wrote this presentation for Sm4rt Security Services&#8217; Tech Day, but I wanted to go further so I wrote it in a way that can be useful for the Pentesters and the Information Security Officers in the company.<\/p>\n<p>In the first part I talk about some basic concepts about SSH then I got for the hacking part so I give a demonstration based on the Mark Baggett&#8217;s post and I finish giving come SSH security tips based on my experience and some articles I found on Internet. I hope you found it interesting.<\/p>\n<p>You can download it from here:<\/p>\n<p><strong><a href=\"http:\/\/hackarandas.com\/security-articles\/SSH.Hacking.and.Good.Practices-Adrian.Puente.Z.pdf\">SSH Hacking and Good.Practices<\/a><\/strong> by <strong>Adrian Puente Z.<\/strong> (PDF Presentation)<\/p>\n<p>Please visit my other <a href=\"http:\/\/hackarandas.com\/hacking-projects\/\">Hacking Projects<\/a> o <a href=\"http:\/\/hackarandas.com\/security-articles\/\">Security Articles<\/a>.<\/p>\n<p>If you have something valuable to add to this presentation, please leave your comment.<\/p>\n<p>References:<\/p>\n<ul>\n<li><a href=\"http:\/\/en.wikipedia.org\/wiki\/Secure_Shell\">Secure Shell from Wikipedia, the free encyclopedia<\/a><\/li>\n<li><a href=\"http:\/\/www.redhat.com\/docs\/manuals\/linux\/RHL-9-Manual\/ref-guide\/s1-ssh-conn.html\">Red Hat Linux 9: Red Hat Linux Reference Guide, Chapter 18. SSH Protocol<\/a> <\/li>\n<li><a href=\"http:\/\/pauldotcom.com\/2010\/04\/capturing-ssh-v1-v2-credential.html\">Capturing SSH V1 &#038; V2 Credentials with a MitM ssh honeypot by Mark Baggett<\/a><\/li>\n<li><a href=\"http:\/\/www.cyberciti.biz\/tips\/linux-unix-bsd-openssh-server-best-practices.html\">Top 20 OpenSSH Server Best Security Practices<\/a><\/li>\n<li><a href=\"http:\/\/www.howtoforge.com\/ssh_key_based_logins_putty\">Key-Based SSH Logins With PuTTY<\/a><\/li>\n<\/ul>\n<p>Adri\u00c3\u00a1n Puente Z.<\/p>\n<p>Technorati Tags:<br \/>\n<a href=\"http:\/\/technorati.com\/tag\/Adrian+Puente+Z.\" rel=\"tag\">Adrian Puente Z.<\/a> <a href=\"http:\/\/technorati.com\/tag\/hackarandas\" rel=\"tag\">hackarandas<\/a> <a href=\"http:\/\/technorati.com\/tag\/SSH\" rel=\"tag\">SSH<\/a> <a href=\"http:\/\/technorati.com\/tag\/hacking\" rel=\"tag\">hacking<\/a> <a href=\"http:\/\/technorati.com\/tag\/Man+in+the+Middle\" rel=\"tag\">Man in the Middle<\/a> <a href=\"http:\/\/technorati.com\/tag\/Best+Practices\" rel=\"tag\">Best Practices<\/a> <a href=\"http:\/\/technorati.com\/tag\/Security\" rel=\"tag\">Security<\/a><\/p>\n\n<div style=\"font-size: 0px; height: 0px; line-height: 0px; margin: 0; padding: 0; clear: both;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>I got to confess that I am a big podcast fan and one I am fond of is PaulDotCom &#8211; Security Weekly (I also hear it while I am jogging) So when I read in the blog the Mark Baggett&#8217;s &hellip; <a href=\"https:\/\/hackarandas.com\/blog\/2010\/06\/11\/ssh-hacking-and-good-practices\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,8,37,4],"tags":[39,23,80,40,38],"class_list":["post-235","post","type-post","status-publish","format-standard","hentry","category-articles","category-hacking","category-presentations","category-security","tag-best-practices","tag-hackarandas","tag-hacking","tag-pauldotcom","tag-ssh"],"_links":{"self":[{"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/posts\/235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/comments?post=235"}],"version-history":[{"count":13,"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/posts\/235\/revisions"}],"predecessor-version":[{"id":248,"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/posts\/235\/revisions\/248"}],"wp:attachment":[{"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/media?parent=235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/categories?post=235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hackarandas.com\/blog\/wp-json\/wp\/v2\/tags?post=235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}