Gentoo Archives: gentoo-hardened

From: "Longman
To: "'gentoo-hardened@l.g.o'" <gentoo-hardened@l.g.o>
Subject: RE: [gentoo-hardened] Hardening SSHD
Date: Wed, 25 Oct 2006 14:32:02
Message-Id: 789E617C880666438EDEE30C2A3E8D10DA7EE2@mailsrvnt05.enet.sharplabs.com
1 > I've seen many recommendations for port knocking, but I feel that's
2 > unnecessarily complex when compared to simply changing the port sshd
3 > listens on. While the use of port knocking no doubt further decreases
4 > your exposure over an alternate sshd port, the difference is only a
5 > small percentage of the benefit you receive from moving away from port
6 > 22 in the first place.
7
8 I've moved most of my public SSH ports off 22 because it reduces by
9 thousandfolds the script kiddies playing with their toys and filling my logs
10 and pipes. There is no more efficient means that will give you such returns
11 with such little effort.
12
13 I only wish I'd done it sooner. Yeah, you'll still get port scanned and
14 someone will snoop around, but that's not in the face of the storm on port
15 22.
16 --
17 gentoo-hardened@g.o mailing list

Replies

Subject Author
Re: [gentoo-hardened] Hardening SSHD Guillaume Castagnino <casta@×××××.info>
Re: [gentoo-hardened] Hardening SSHD Panagiotis Atmatzidis <p.atmatzidis@×××××.com>