<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>Linux Format forums</title>
  <link>http://linuxformat.com/forums/index.php</link>
  <description>Help, discussion, magazine feedback and more</description>
  <language>english</language>
  <copyright>(c) Copyright Sat May 25, 2013 6:47 am by Linux Format forums</copyright>
  <managingEditor>webmaster@linuxformat.com</managingEditor>
  <webMaster>webmaster@linuxformat.com</webMaster>
  <pubDate>Sat May 25, 2013 6:47 am</pubDate>
  <lastBuildDate>Sat May 25, 2013 6:47 am</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>Linux Format forums</title>
    <url></url>
    <link>http://linuxformat.com/forums/</link>
    <description>Help, discussion, magazine feedback and more</description>
  </image>

                                      <item>
                                        <title>Update</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=105885#105885</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=67972'&gt;nigel.taylor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Fri May 11, 2012 11:15 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Excellent, I ahve just done that and everything still seems to be running okay.&lt;br /&gt;
&lt;br /&gt;
Thank you very much for you help.&lt;br /&gt;
&lt;br /&gt;
Much Appreciated.&lt;br /&gt;
&lt;br /&gt;
Nigel</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=105885#105885</comments>
                                        <author>nigel.taylor</author>
                                        <pubDate>Fri May 11, 2012 11:15 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=105885#105885</guid>
                                      </item>
                                      <item>
                                        <title>Re: Update</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=105884#105884</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=2793'&gt;MartyBartfast&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Fri May 11, 2012 11:11 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;nigel.taylor wrote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;&lt;br /&gt;
Would I be right in saying that I just need to comment out the line reading Port 443 and restart the SSH Service?&lt;br /&gt;
&lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
Yes.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=105884#105884</comments>
                                        <author>MartyBartfast</author>
                                        <pubDate>Fri May 11, 2012 11:11 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=105884#105884</guid>
                                      </item>
                                      <item>
                                        <title>Update</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=105883#105883</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=67972'&gt;nigel.taylor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Fri May 11, 2012 11:03 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hi Guys,&lt;br /&gt;
&lt;br /&gt;
I have had a look in /etc/ssh/sshd_config and yes in there is a section that reads&lt;br /&gt;
&lt;br /&gt;
#What ports, IPs and protocols we listen for&lt;br /&gt;
Port 22&lt;br /&gt;
Port 443&lt;br /&gt;
&lt;br /&gt;
Would I be right in saying that I just need to comment out the line reading Port 443 and restart the SSH Service?&lt;br /&gt;
&lt;br /&gt;
Regards,&lt;br /&gt;
&lt;br /&gt;
Nigel</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=105883#105883</comments>
                                        <author>nigel.taylor</author>
                                        <pubDate>Fri May 11, 2012 11:03 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=105883#105883</guid>
                                      </item>
                                      <item>
                                        <title>Re: Disabling SSH via Port 443</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=105829#105829</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=2793'&gt;MartyBartfast&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun May 06, 2012 10:12 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;purplepenguin wrote:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;quote&quot;&gt;&lt;br /&gt;
Log into your router's admin page and disable port forwarding from port 443&lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
You probably don't want to do that. If you're intending this server to be a webserver then you almost certainly will need port 443 forwarded, which is presumable why this guy chose to have ssh listening on that port , as that he knew he could always get through the router.&lt;br /&gt;
&lt;br /&gt;
I agree with editing /etc/ssh/sshd_config and comment out anything that looks like &amp;quot;Port 443&amp;quot;, it should normally listen on port 22, so there will probably be a line in there for that which can be left, but I would be suspicious of any other port definitions.&lt;br /&gt;
&lt;br /&gt;
Note there may also be a line something like&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;&lt;br /&gt;
Listen 1.2.3.4&amp;#58;443 &lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
which might also need to be removed.&lt;br /&gt;
&lt;br /&gt;
The best way to remove these lines is to stick a &amp;quot;#&amp;quot; at the start of the line, then they become comments and you can easily put everything back if you screw up.&lt;br /&gt;
&lt;br /&gt;
Once you've edited sshd_config you need to restart sshd, I can't remember how to do that in Ubuntu but if you can reboot the box then that will do it.&lt;br /&gt;
&lt;br /&gt;
As for passwords, if you don't trust this person then the only option you have is to change ALL the passwords, on top of which he may be using an ssh key, so things get more complicated as it's possible you've got legitimate internal ssh keys and they can be virtually impossible to identify where they came from.&lt;br /&gt;
&lt;br /&gt;
[/code]</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=105829#105829</comments>
                                        <author>MartyBartfast</author>
                                        <pubDate>Sun May 06, 2012 10:12 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=105829#105829</guid>
                                      </item>
                                      <item>
                                        <title>Re: Disabling SSH via Port 443</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=105823#105823</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=67727'&gt;purplepenguin&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun May 06, 2012 7:11 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hi I use ssh and sshfs on my home LAN I am not a ssh guru but this is what I would try. &lt;br /&gt;
&lt;br /&gt;
Log into your router's admin page and disable port forwarding from port 443&lt;br /&gt;
&lt;br /&gt;
Look in /etc/ssh/ssh.config or sshd.config look for refs to port 443 and read the comments. If confident either change or comment out the 443 referances.&lt;br /&gt;
&lt;br /&gt;
Do you know which account the person would log on through? and do they use a password or rsa key?&lt;br /&gt;
If say they log on via an account called admin with a password change the password. If they created their own account to administer your server remotely you could disable or remove the account. &lt;br /&gt;
&lt;br /&gt;
If you want to change another user accounts password logon to your system as root and &lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;# passwd username&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
you will then be asked to enter and re-enter a new unix password for that user account.&lt;br /&gt;
&lt;br /&gt;
Good luck&lt;br /&gt;
&lt;br /&gt;
[/code]</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=105823#105823</comments>
                                        <author>purplepenguin</author>
                                        <pubDate>Sun May 06, 2012 7:11 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=105823#105823</guid>
                                      </item>
                                      <item>
                                        <title>Disabling SSH via Port 443</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=105715#105715</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=67972'&gt;nigel.taylor&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Wed May 02, 2012 6:04 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hi Guys,&lt;br /&gt;
&lt;br /&gt;
Basically I am very much in the newbie catagory in terms of Linux skills.&lt;br /&gt;
&lt;br /&gt;
Basically we had a contractor in who setup a Ubunut Server up for us and I know he enabled himself to access the server from home by proxying through port 443. The contractor no longer works for us.&lt;br /&gt;
&lt;br /&gt;
Is anyone able to advise me on where I can look on the server to get this disabled? The server in question is going to be used as a webserver.&lt;br /&gt;
&lt;br /&gt;
Nigel</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=105715#105715</comments>
                                        <author>nigel.taylor</author>
                                        <pubDate>Wed May 02, 2012 6:04 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=105715#105715</guid>
                                      </item></channel></rss>