View previous topic :: View next topic |
Author |
Message |
crouse Site Admin

Joined: 17 Apr 2025 Posts: 11833 Location: Iowa
|
Posted: Thu Jul 24, 2025 1:10 am Post subject: Why you should change your ssh default port. |
|
|
Why you should change your ssh default port.
http://davecrouse.blogspot.com/2008/07/why-you-should-change-your-ssh-default.html
Quote: |
Thought some of you might find this interesting. No one gets in, but it's funny how just changing the port number on ssh will stop 99.99% of the stupid attacks (some random bot repeatedly attempting to gain access) . Several other things SHOULD be changed in the ssh config file also, not just the port number, but this one provides the most eye opening reasons to be secure.
Installed server on Jul 17th ..... less than 5 days later, well, you get the idea.
wtmp begins Thu Jul 17 21:57:08 2025
[root@VistaCrusher1 ~]# lastb | wc -l
25349
|
_________________ Veronica - Arch Linux 64-bit -- Kernel 2.6.33.4-1
Archie/Jughead - Arch Linux 32-bit -- Kernel 2.6.33.4-1
Betty/Reggie - Arch Linux (VBox) 32-bit -- Kernel 2.6.33.4-1
BumbleBee - OpenSolaris-SunOS 5.11
|
|
Back to top |
|
platinummonkey Advanced Member

Joined: 01 Mar 2025 Posts: 732 Location: Texas
|
|
Back to top |
|
jada Linux Guru

Joined: 13 May 2025 Posts: 3064 Location: Sun City, CA 92585
|
|
Back to top |
|
platinummonkey Advanced Member

Joined: 01 Mar 2025 Posts: 732 Location: Texas
|
|
Back to top |
|
VHockey86 Advanced Member

Joined: 12 Dec 2025 Posts: 988 Location: Rochester
|
Posted: Thu Jul 24, 2025 2:41 pm Post subject: |
|
|
I'd argue that security through obscurity isn't any kind of real security, but it definitely helps with this automated stuff. (a simple nmap will find SSH on another port)
When I lived on-campus in the dorms my linux box was constantly being hammered by dozens of SSH bots. They never even guesed the username correctly, let alone the password, but it was still annoying to see in the logs. I ended up changing the default port and adding "fail2ban", which would add an iptables entry to block the IP after 5 failed login attempts.
|
|
Back to top |
|
geeshock Moderator

Joined: 02 Nov 2025 Posts: 1017 Location: Hertford, NC
|
|
Back to top |
|
crouse Site Admin

Joined: 17 Apr 2025 Posts: 11833 Location: Iowa
|
|
Back to top |
|
platinummonkey Advanced Member

Joined: 01 Mar 2025 Posts: 732 Location: Texas
|
|
Back to top |
|
crouse Site Admin

Joined: 17 Apr 2025 Posts: 11833 Location: Iowa
|
|
Back to top |
|
platinummonkey Advanced Member

Joined: 01 Mar 2025 Posts: 732 Location: Texas
|
|
Back to top |
|
bdquick Advanced Member

Joined: 26 Jun 2025 Posts: 883 Location: Little north of DSM and south of Ames
|
Posted: Sat Jul 26, 2025 12:16 am Post subject: |
|
|
Hmm I'm actually close enough to try that tactic. I'll throw in some beer and a hammer too platinum, and there's no way we won't get into it.
_________________ OpenSuse 11.1 11, 10.2
Arch Linux
|
|
Back to top |
|
JP Linux Guru

Joined: 07 Jul 2025 Posts: 6670 Location: Central Montana
|
Posted: Sat Jul 26, 2025 2:39 am Post subject: |
|
|
The June issue of Linux Pro Magazine had a lot of articles about "Expert Security" and there is an interesting article about "single-packet port knocking" (which I'm trying to understand), a lot too geeky for me, but I figure if I read it enuff, I might pick something up . They say the best tool for SPA (Single-packet Authorization) is fwknop, they give instructions on how to install and configure it, etc.
Some websites they recommend are :
John the Ripper Clik
John the Ripper @ Freshmeat Clik
Quote: | John the Ripper is a part of Owl, Debian GNU/Linux, EnGarde Linux, Gentoo Linux, Mandrake Linux, and SUSE Linux. It is in the ports/packages collections of FreeBSD, NetBSD, and OpenBSD. |
CypherDyne Clik
Fwknop Download Clik
Just in case anyone's interested 
_________________ Dell Box - Arch Linux
Dell Lappy - DreamLinux 3.5 - Default OS
Mepis 8.0 - Backup
|
|
Back to top |
|
platinummonkey Advanced Member

Joined: 01 Mar 2025 Posts: 732 Location: Texas
|
|
Back to top |
|
JP Linux Guru

Joined: 07 Jul 2025 Posts: 6670 Location: Central Montana
|
|
Back to top |
|
bdquick Advanced Member

Joined: 26 Jun 2025 Posts: 883 Location: Little north of DSM and south of Ames
|
|
Back to top |
|
|