3 ms·
I've been running non-standard ports for a few years and while it certainly cuts down on the non-stop brutes on 22, my servers still get smacked pretty often in
by dp30 9y ago
I've been running non-standard ports for a few years and while it certainly cuts down on the non-stop brutes on 22, my servers still get smacked pretty often in 400-500 attempt blocks.
- throwaway613834 9y agoOh, interesting. Are your servers targets of interest somehow? Or are your ports possibly still low numbers?
- dp30 9y agodefinitely not interesting, but they're on port 8022 so maybe that's a common one for attack scanners. i mean with masscan its so fast and easy to find ssh ports, i cant imagine any non-standard port is more obscure than the next. they are hosted on a low cost vps provider so maybe their ranges are common low hanging fruit.
- throwaway613834 9y agoI wouldn't have revealed the exact port number here, but thanks :) yeah, I think your explanation sounds plausible.
- firethief 9y agoA port number isn't a real secret, it just screens out the bulk of mass scans. There's no point trying to hide it from targeted attackers.
- user5994461 9y agoThe hosting providers have known IP ranges and they are scanned permanently. I wouldn't be surprised if some guys had a rule to try 8022 and the most common non standard ports.