Change SSH password a must?

Discussion in 'Jailbreaks and iOS Hacks' started by HiFiGuy528, Aug 6, 2010.

  1. HiFiGuy528 macrumors 68000

    HiFiGuy528

    Joined:
    Jul 24, 2008
    #1
    All it installed are PdaNet & My3G on my iPhone 4. Did not install any SSH apps. Am I open to the public just by using JailbreakMe.com?
     
  2. mustnotsleep macrumors 6502

    Joined:
    Apr 3, 2010
  3. maturola macrumors 68040

    maturola

    Joined:
    Oct 29, 2007
    Location:
    Atlanta, GA
    #3
    If you are running SSH, them yes it is a must. But based on what you listed, you did not installed OpenSSH.

    having the password to default is like having a Open wifi network, or leaving the door of your house unlock. You may be lucky and nothing will happend, but someone can take advantage of that and screw your device.

    No long ago there was a worm (Ikee) that scam the network for jailbroken devices with default SSH password and it was changing the background (nothing real bad, since he actually could have do much much worst) but he was trying to prove a point.
     
  4. dhlizard macrumors G4

    dhlizard

    Joined:
    Mar 16, 2009
    Location:
    The Jailbreak Community
    #4
    There is a big exploit in iOS 4 firmware which jailbreak me uses for jailbreak. If you are on iOS 4 you have it.

    Sounds like you are confusing this with OpenSSH password issues. If you have OpenSSH installed on your phone, it is a must that you change both the root and mobile password.
     
  5. -MRB macrumors 6502

    Joined:
    Jul 1, 2010
    Location:
    UK
    #5
    I tried doing this the other day.


    Mobile Terminal crashes upon opening.

    And when i try to SSH on my computer, and run the passwd command, it times out?
     
  6. Mystikal macrumors 68020

    Mystikal

    Joined:
    Oct 4, 2007
    Location:
    Irvine, CA
    #6
    Whats the command again?
     
  7. vladzaharia macrumors regular

    Joined:
    Jul 5, 2010
    #7
    It was said in the post you quoted: passwd
     
  8. spamdumpster macrumors 6502a

    Joined:
    Jan 22, 2008
    #8
    The version of MobileTerminal in Cydia won't work on iOS 4. Google MobileTerminal 426, and you'll find one that does.
     
  9. ulbador macrumors 68000

    ulbador

    Joined:
    Feb 11, 2010
    #9
    Generally the time out occurs because your phone goes to sleep. You have to keep the screen awake and alive long enough to change your passwd.
     
  10. Bakakage macrumors 6502

    Joined:
    Jun 18, 2009
    #10
    Here is a super easy way to change your ssh password. Install rock from Cydia and it will detect your default alpine password and tell you if you want to change your password when you open rock. Just change it from there and then unistall it. The password will still be changed when you uninstall it.
     
  11. mlts22 macrumors 6502a

    Joined:
    Oct 28, 2008
    #11
    Here is what I did to make sure the SSH password is locked down:

    1: Download and install the Mobile Terminal 426 Debian package.
    2: Install sudo via Cydia, and add

    ALL = (ALL) NOPASSWD: ALL

    via the visudo command. This will you to bypass entering the root password by using sudo -i.

    3: Change both the mobile user and the root user's passwords. I'd say minimum, 20 characters, realistically 32-48 characters. Just make sure you have both copied down somewhere to be safe.

    4: Set /etc/sshd/sshd_config to disallow ssh in as root, disallow ssh in with any password (public key authentication only), and disable it in SBSettings when I can. This should keep almost anyone out, unless there is a zero-day hole in ssh. Maybe changing the port would help, but a decent blackhat likely has run nmap on the box and found where it likely moved to, so I didn't bother.

    With these steps, the sshd is still usable for sftp and other items, but using RSA keys, so an attacker is unable to do a brute force attack on the passwords.
     
  12. HiFiGuy528 thread starter macrumors 68000

    HiFiGuy528

    Joined:
    Jul 24, 2008
    #12
    I am not worried about the PDF hole in Safari.

    So since I did NOT install OpenSSH or Terminal app, I don't have to worry about leaving my door unlocked right?
     
  13. qckslvrsiete macrumors regular

    Joined:
    Jun 22, 2010
    #13
    or open cydia and add http://cydia.xsellize.com as a source, then search for mobileterminal ios4. I used that to change my passwd
     
  14. joetwizzy macrumors member

    Joined:
    Sep 12, 2008
    #14
    Just a quick related question.

    As I understand apple set 'apline' as the default root password. So would changing it ever break/confuse any apple applications that need to use root (if there is any)?
     
  15. sico macrumors newbie

    Joined:
    Aug 3, 2010
    #15
    simples!!
     
  16. Mystikal macrumors 68020

    Mystikal

    Joined:
    Oct 4, 2007
    Location:
    Irvine, CA
    #16
    Ive never had any problems with a change password.
     
  17. dieburnbot macrumors 6502a

    dieburnbot

    Joined:
    Aug 18, 2008
    Location:
    CA
    #17
    I have the default password set, but I make sure to turn it off via sbsettings everytime my phone gets rebooted, which isn't very often. I only turn it on when I need it.
     

Share This Page