3 ms·
So running your SSH daemon on a port other than 22 will never be better than doing something above patching, a solid config, and key or cert-based auth? I disa
by danielrm26 10y ago
So running your SSH daemon on a port other than 22 will never be better than doing something above patching, a solid config, and key or cert-based auth?
I disagree.
If you're listening you are potentially vulnerable to an 0day that is simply far less likely to hit you on 2222 than 22---especially before you hear about others getting pwned and have time to patch.
If you harden to a certain point (like the list above), the next best thing MAY be to get out of the line of fire, either by moving your listener or putting up a portknocker system or something.