greetings.
first i have been member a decade. bad at password email remembering so have had 4 accounts!
my experience and server info:
using cpanel since 2001. have pretty much run servers since 1998, online 1992.
server using csf, modsec, exploit scanner, hardened passwords. most security items checked and altered to correct security. no usr shell or jail shell, no 777 files, dovecot, pure ftp, non sftp. . server has 30 accounts we own.
first
1) decided to use pub keys. set it up, works fine as long as we place root in "data" in putty and have #rootlogin yes --with/or without "#"
2) works with authentication "no" in webhostmgr and ssh config file works fine as long as #rootlogin yes --with/or without "#"
3) when logging in, it says "root" using public key.
4) when we turn off root login, it returns a statement "though key is recognized by server, server is not accepting key" [not exact statement words, been 22hrs]
5) if we change to "#allowrootlogin yes"
6) works flawlessly
second
7) during the many hours i ran chkroot and rkhunter.
rkhunter provided warnings including
warning dovecot-wrap*
warning jailexec*
warning jailshell
these are just "warning"
8)when i checked the files in the directory
/usr/local/cpanel/bin/adduser
9) these are highlighted "red" like a stroke from red highlighter
dovecot-wrap*
jailexec*
jailshell
again, they are all highlighted in "red"
10) i spent 5 hours trying to discover if these files should be highlighted red .. i cannot remember ever seeing this.
i checked file chmod/chown.
when i made backups, such as jailshell-backup, they also were in red.
so,
10- any comment on red highlighter looking files
11- with vi/pico should all three be text script files?
[sounds crazy but i am that confused, vi and one look like half binary with text]
12 any comment on shell keys with root login yes verses no
thanks in advance. i could never have operated my own servers w/o this great forum.
rock scarfone
goldsmithworks
first i have been member a decade. bad at password email remembering so have had 4 accounts!
my experience and server info:
using cpanel since 2001. have pretty much run servers since 1998, online 1992.
server using csf, modsec, exploit scanner, hardened passwords. most security items checked and altered to correct security. no usr shell or jail shell, no 777 files, dovecot, pure ftp, non sftp. . server has 30 accounts we own.
first
1) decided to use pub keys. set it up, works fine as long as we place root in "data" in putty and have #rootlogin yes --with/or without "#"
2) works with authentication "no" in webhostmgr and ssh config file works fine as long as #rootlogin yes --with/or without "#"
3) when logging in, it says "root" using public key.
4) when we turn off root login, it returns a statement "though key is recognized by server, server is not accepting key" [not exact statement words, been 22hrs]
5) if we change to "#allowrootlogin yes"
6) works flawlessly
second
7) during the many hours i ran chkroot and rkhunter.
rkhunter provided warnings including
warning dovecot-wrap*
warning jailexec*
warning jailshell
these are just "warning"
8)when i checked the files in the directory
/usr/local/cpanel/bin/adduser
9) these are highlighted "red" like a stroke from red highlighter
dovecot-wrap*
jailexec*
jailshell
again, they are all highlighted in "red"
10) i spent 5 hours trying to discover if these files should be highlighted red .. i cannot remember ever seeing this.
i checked file chmod/chown.
when i made backups, such as jailshell-backup, they also were in red.
so,
10- any comment on red highlighter looking files
11- with vi/pico should all three be text script files?
[sounds crazy but i am that confused, vi and one look like half binary with text]
12 any comment on shell keys with root login yes verses no
thanks in advance. i could never have operated my own servers w/o this great forum.
rock scarfone
goldsmithworks