1 |
> I've seen many recommendations for port knocking, but I feel that's |
2 |
> unnecessarily complex when compared to simply changing the port sshd |
3 |
> listens on. While the use of port knocking no doubt further decreases |
4 |
> your exposure over an alternate sshd port, the difference is only a |
5 |
> small percentage of the benefit you receive from moving away from port |
6 |
> 22 in the first place. |
7 |
|
8 |
I've moved most of my public SSH ports off 22 because it reduces by |
9 |
thousandfolds the script kiddies playing with their toys and filling my logs |
10 |
and pipes. There is no more efficient means that will give you such returns |
11 |
with such little effort. |
12 |
|
13 |
I only wish I'd done it sooner. Yeah, you'll still get port scanned and |
14 |
someone will snoop around, but that's not in the face of the storm on port |
15 |
22. |
16 |
-- |
17 |
gentoo-hardened@g.o mailing list |