TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

OVH's Maintenance SSH Keys compromised

31 pointsby jawralmost 13 years ago

10 comments

alxalmost 13 years ago
False alert:<p>The information is wrong, and OVH was right. I hereby apology for the mistake. See this for more details. FS#7060 — Debian: log d'authentification SSH incorrect. <a href="http://travaux.ovh.net/?do=details&#38;id=7060&#38;edit=yep" rel="nofollow">http://travaux.ovh.net/?do=details&#38;id=7060&#38;edit=yep</a>
Loicalmost 13 years ago
I have the same trace in my logs and I disabled the key for the moment. For a quick translation because the page is in French:<p>If you have a server with OVH, they setup by default a secondary SSH key in /root/.ssh/authorized_keys2 which is allowed to access your server only from a single IPv4 and a single IPv6. This is to allow debugging of your server.<p>It looks like the private key has been compromised and is now used to try to access the servers from another IP. Your server will not be compromised, but by security, better to disable this extra key by renaming the file "authorized_keys2.disabled".<p>You can check your logs with a grep like this:<p><pre><code> # grep "correct" /var/log/auth.log Jul 17 21:42:49 node1 sshd[18548]: Authentication tried for root with correct \ key but not from a permitted host (host=178.63.21.XXX, ip=178.63.21.XXX).</code></pre>
评论 #4270553 未加载
byrootalmost 13 years ago
It seems to be an SSH bug <a href="http://linuxfr.org/nodes/94898/comments/1369391" rel="nofollow">http://linuxfr.org/nodes/94898/comments/1369391</a><p>If there is a "from" filter on a key in case of failure this message appear even if the key don't match.
_Lemon_almost 13 years ago
I just fired off an e-mail to OVH to see their response (and to probably make them more aware of this).<p>OVH pre-install a number of things by default on their Debian image including monitoring software (it integrates into their manager) and this key.<p>The only way to make sure things like this are a non-issue is to do a clean install yourself, e.g., via debootstrap in "rescue pro mode".<p>You can then install the key on their request if required giving you more control.
评论 #4270608 未加载
评论 #4270556 未加载
giulianobalmost 13 years ago
Just don't leave your SSH service open to the internet. Set yourself up a VPN and block SSH to your internal LAN.
评论 #4270606 未加载
joe_bleaualmost 13 years ago
Oops. Google translate link: <a href="http://translate.google.com/translate?client=opera&#38;ie=UTF8&#38;oe=UTF8&#38;sl=fr&#38;tl=en&#38;u=http://www.pps.univ-paris-diderot.fr/~kerneis/ovh-ssh-key/" rel="nofollow">http://translate.google.com/translate?client=opera&#38;ie=UT...</a>
iSlothalmost 13 years ago
Fortunately there is a default IP limitation in place, however it's still worrying.
electrotypealmost 13 years ago
Thanks, I disabled the SSH key until more information is available.
vinialmost 13 years ago
It's just a debian log bug
stonnyfrogsalmost 13 years ago
Nothing on my logs. FreeBSD.