Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Thu Jul 07, 2011 9:46 pm 
Offline
Senior Member

Joined: Wed Mar 03, 2010 2:04 pm
Posts: 111
I run an SSH tunnel through my Linode from home. Tonight I upgraded the firmware on my router, and immediately afterward when I went to connect to my Linode with PuTTY, I got a warning that my key fingerprint had changed. From Android, ConnectBot says this might be a man-in-the-middle attack (similar warning).

I'm guessing (emphasis on guessing) that this relates somehow to my router firmware upgrade, just given the timing, but on the other hand, why would that have any effect on the Linode's RSA key fingerprint? It doesn't make sense to me other than the fact that the router does sit "in the middle" of this connection. When I connect to my Linode using a device off my LAN (my smartphone), I get no warning, and the key as reported by "ssh localhost" is different than the one reported when I connect from my LAN.

In short, how worried should I be? I suppose I have some reading to do before I understand this, but I'm hoping someone can shed some insight.


Top
   
 Post subject:
PostPosted: Fri Jul 08, 2011 6:35 pm 
Offline
Senior Member

Joined: Wed Mar 03, 2010 2:04 pm
Posts: 111
Edit: solved, this was a firewall rule on my router that was redirecting traffic to an internal IP address, so that explains why the RSA fingerprint changed - it was indeed a different machine.


Top
   
 Post subject:
PostPosted: Sat Jul 09, 2011 5:44 am 
Offline
Senior Member
User avatar

Joined: Tue Nov 24, 2009 1:59 pm
Posts: 362
o_O

"Internal IP address" as in another machine on your LAN, or as in some crazy man-in-the-middle thing in the new router firmware itself?

_________________
rsk, providing useless advice on the Internet since 2005.


Top
   
 Post subject:
PostPosted: Sat Jul 09, 2011 5:45 pm 
Offline
Senior Member

Joined: Wed Mar 03, 2010 2:04 pm
Posts: 111
machine on my lan, listening on the same port. due to the router setting being incorrect it was redirecting me to that machine. fixing the setting solved the issue. it related to the firmware update as that never happened before.


Top
   
 Post subject:
PostPosted: Sat Jul 09, 2011 11:23 pm 
Offline
Senior Member
User avatar

Joined: Tue Nov 24, 2009 1:59 pm
Posts: 362
Okay, thanks.
brain# sysctl paranoia.conspiracy.enabled=0
:wink:

_________________
rsk, providing useless advice on the Internet since 2005.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group