{"id":3976,"date":"2015-04-11T19:02:32","date_gmt":"2015-04-11T17:02:32","guid":{"rendered":"http:\/\/www.collet-matrat.com\/?p=3976"},"modified":"2015-04-11T19:02:32","modified_gmt":"2015-04-11T17:02:32","slug":"1-serveur-ssh-1-mot-de-passe-trivial-quelle-duree-de-vie","status":"publish","type":"post","link":"https:\/\/www.collet-matrat.com\/?p=3976","title":{"rendered":"1 serveur SSH &#8211; 1 mot de passe trivial &#8211; quelle dur\u00e9e de vie ?"},"content":{"rendered":"<p style=\"text-align: justify;\"><a href=\"https:\/\/i0.wp.com\/www.collet-matrat.com\/wp-content\/uploads\/2015\/04\/honeypot.jpg?ssl=1\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\" size-full wp-image-3977 aligncenter\" src=\"https:\/\/i0.wp.com\/www.collet-matrat.com\/wp-content\/uploads\/2015\/04\/honeypot.jpg?resize=584%2C362&#038;ssl=1\" alt=\"honeypot\" width=\"584\" height=\"362\" srcset=\"https:\/\/i0.wp.com\/www.collet-matrat.com\/wp-content\/uploads\/2015\/04\/honeypot.jpg?w=609&amp;ssl=1 609w, https:\/\/i0.wp.com\/www.collet-matrat.com\/wp-content\/uploads\/2015\/04\/honeypot.jpg?resize=300%2C186&amp;ssl=1 300w, https:\/\/i0.wp.com\/www.collet-matrat.com\/wp-content\/uploads\/2015\/04\/honeypot.jpg?resize=483%2C300&amp;ssl=1 483w\" sizes=\"auto, (max-width: 584px) 100vw, 584px\" \/><\/a>Tout le monde le sait : il ne faut jamais exposer un serveur SSH sur le net avec un mot de passe \"trivial\". Mais dans les faits, en combien de temps un tel serveur est-il exploit\u00e9 par des personnes mal intentionn\u00e9es ? C'est ce que j'ai essay\u00e9 de d\u00e9terminer en mettant en place un petit <a href=\"https:\/\/fr.wikipedia.org\/wiki\/Pot_de_miel\" target=\"_blank\">honeypot<\/a> ...<\/p>\n<p style=\"text-align: justify;\">Le test\u00a0 a \u00e9t\u00e9 r\u00e9alis\u00e9 sur un serveur install\u00e9 sp\u00e9cifiquement pour cette op\u00e9ration (Debian 7) en utilisant une adresse IP publique inexploit\u00e9e depuis plusieurs ann\u00e9es. J'ai modifi\u00e9 mon <em>.bashrc<\/em> pour recevoir un email lorsqu'une session SSH \u00e9tait active sur ce serveur (utilisateur connect\u00e9 en \"root\"). Afin de ne pas prendre de risques, ce serveur \u00e9tait \u00e9galement param\u00e9tr\u00e9 pour s'\u00e9teindre automatiquement d\u00e8s qu'une session SSH \u00e9tait active (on ne sait jamais ...). Enfin j'ai tout simplement choisi (pour le compte \"root\")\u00a0 <a href=\"http:\/\/www.journaldugeek.com\/2015\/01\/20\/123456-reste-le-mot-de-passe-le-plus-utilise-en-2014\/\" target=\"_blank\">le mot de passe le plus utilis\u00e9 en 2014<\/a> : \"<em>123456<\/em>\". Difficile de faire moins s\u00e9curis\u00e9 \ud83d\ude42<\/p>\n<p style=\"text-align: justify;\">Le serveur a \u00e9t\u00e9 mis en ligne le 27 mars \u00e0 17h20. La premi\u00e8re connexion SSH d\u00e9tect\u00e9e\u00a0 (et r\u00e9ussie) a eu lieu le 28 mars \u00e0 5h40. <strong>Le serveur a donc \u00e9t\u00e9 rep\u00e9r\u00e9, test\u00e9 et acc\u00e9d\u00e9 en 12h et 20mn<\/strong> !<\/p>\n<p style=\"text-align: justify;\">Cette exp\u00e9rience montre que le choix d'un mot de passe complexe est particuli\u00e8rement important. En mati\u00e8re de connexion SSH, l'usage de cl\u00e9s (et l'interdiction des mots de passe) me semble m\u00eame \u00eatre un imp\u00e9ratif.<\/p>\n<ul>\n<li style=\"text-align: justify;\">Cr\u00e9dit photo : <a href=\"https:\/\/www.flickr.com\/photos\/vlastimil_koutecky\/12361255373\/in\/faves-18689371@N00\/\" target=\"_blank\">Vlastimil Kouteck\u00fd<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Tout le monde le sait : il ne faut jamais exposer un serveur SSH sur le net avec un mot de passe \"trivial\". Mais dans les faits, en combien de temps un tel serveur est-il exploit\u00e9 par des personnes mal &hellip; <a href=\"https:\/\/www.collet-matrat.com\/?p=3976\">Lire la suite <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"Sur le blog : \"1 serveur SSH - 1 mot de passe trivial - quelle dur\u00e9e de vie ?\"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[86],"tags":[],"class_list":["post-3976","post","type-post","status-publish","format-standard","hentry","category-securite"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_likes_enabled":true,"_links":{"self":[{"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=\/wp\/v2\/posts\/3976","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3976"}],"version-history":[{"count":4,"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=\/wp\/v2\/posts\/3976\/revisions"}],"predecessor-version":[{"id":3981,"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=\/wp\/v2\/posts\/3976\/revisions\/3981"}],"wp:attachment":[{"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3976"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3976"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.collet-matrat.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3976"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}