The Following User Says Thank You to momcilo For This Useful Post: | ||
![]() |
2011-06-15
, 18:21
|
|
Posts: 1,411 |
Thanked: 1,330 times |
Joined on Jan 2010
@ Tatooine
|
#22
|
PasswordAuthentication no UsePAM no
The Following 4 Users Say Thank You to jedi For This Useful Post: | ||
![]() |
2011-06-15
, 18:29
|
Posts: 135 |
Thanked: 75 times |
Joined on Apr 2011
@ Buenos Aires, Argentina
|
#23
|
Using passwords sucks big time. To prevent against a scripted password-guessing bot, just disable password login on your N900 and only use keys.
edit (as root) /etc/ssh/sshd_config:
To use key based authentication: http://www.google.com/search?q=ssh+login+no+passwordCode:PasswordAuthentication no UsePAM no
edit: woowoo post 1,000!
![]() |
2011-06-15
, 18:46
|
Posts: 673 |
Thanked: 856 times |
Joined on Mar 2006
|
#24
|
The Following 2 Users Say Thank You to momcilo For This Useful Post: | ||
![]() |
2011-06-15
, 19:11
|
|
Posts: 1,411 |
Thanked: 1,330 times |
Joined on Jan 2010
@ Tatooine
|
#25
|
I've just checked the freemantle repository.
Openssh is version 5.1p1
There are at least 3 published problems with security.
And OpenSSl is 0.9.8n, it also has 3 published issues.
The Following User Says Thank You to jedi For This Useful Post: | ||
![]() |
2011-06-15
, 19:24
|
Posts: 135 |
Thanked: 75 times |
Joined on Apr 2011
@ Buenos Aires, Argentina
|
#26
|
![]() |
2011-06-15
, 20:02
|
Posts: 673 |
Thanked: 856 times |
Joined on Mar 2006
|
#27
|
![]() |
2011-06-15
, 20:43
|
Posts: 673 |
Thanked: 856 times |
Joined on Mar 2006
|
#28
|
![]() |
2011-06-15
, 21:00
|
|
Posts: 187 |
Thanked: 96 times |
Joined on Sep 2010
@ London, UK
|
#29
|
![]() |
2011-06-15
, 21:41
|
Posts: 673 |
Thanked: 856 times |
Joined on Mar 2006
|
#30
|
Does our openvpn client have any known vulnerabilities?(let's assume the server is secure)
Can user/group nobody be set up on client side if server is not *NIX. Would chroot work client side only in the same scenario?
Is there any way to log keystrokes through a browser in N900?
Sandboxing Maemo's browsers?
Just some questions that I'd love to hear your opinion about.
The Following User Says Thank You to momcilo For This Useful Post: | ||
Here is the official OpenSSH link:
http://www.openssh.org/security.html
http://gpl-violations.org/faq/violation-faq.html