4 ms·
Better yet, deploy OSSEC there. I would recommend it with the latest patches from here: https://dcid.me/ossec/ https://dcid.me/ossec/
by rmdoss 11y ago
Better yet, deploy OSSEC there. I would recommend it with the latest patches from here:
https://dcid.me/ossec/ https://dcid.me/ossec/
- matt_wulfeck 11y agoIt's just another thing you need running on the server that must stay patched forever. In my opinion less is better. RSA/4096-bit key encryption only. I don't even care if you use the root user. The ability for someone to crack a 4096-bit key is impossible in practice, and if your SSH server has a bug then it doesn't matter what fancy things you have setup.
- rmdoss 11y agoIt is fine for a 1-man server, but if you have multiple users and you have to be on top of things, then you need a bit more than that. Specially to look at successful logins and audit where they come from. This is a good blog post on the subject: https://blog.sucuri.net/2016/03/server-security-anomaly-behaviour-with-ossec.html https://blog.sucuri.net/2016/03/server-security-anomaly-beha...