4 ms·
I just harden my sshd config based on https://github.com/arthepsy/ssh-audit https://github.com/arthepsy/ssh-audit and ALL bots will fail since they do not suppo
by YouKnowBetter 9y ago
I just harden my sshd config based on https://github.com/arthepsy/ssh-audit https://github.com/arthepsy/ssh-audit and ALL bots will fail since they do not support the more current config os key-exchange, host-key, encryption and message authentication code algorithms.
To make it even more interesting: one can actually see which bot is trying by the way they fail to handshake.
I like a litte noice on my ports so leave ssh on its default port, accept authentication only with a certificate and be done. Works like a charm. And yes it makes my sshd stand out like a sour thumb since 99.9% (guestimation) of you folks don't tighten up your ssh configs :)