4 ms·
The biggest losers are most likely: the bots. I update my sshd configs untill they're green [0] and love to see the bots fail with even establishing a connecti
by YouKnowBetter 9y ago
The biggest losers are most likely: the bots.
I update my sshd configs untill they're green [0] and love to see the bots fail with even establishing a connection. You can even distinguish the different bot families by their (limited) protocols.
[0] https://github.com/arthepsy/ssh-audit https://github.com/arthepsy/ssh-audit
- mrsteveman1 9y agoVery nice tool, I hadn't seen that before thanks! There should be a service similar to Mozilla's TLS configuration generator[1], but for SSH. Mozilla does have a wiki page with modern and intermediate SSH configurations[2], but I'm not sure whether the advice is still current, and a configuration generator page would probably be more accessible. I wonder if they would be open to creating one. [1] https://mozilla.github.io/server-side-tls/ssl-config-generator/ https://mozilla.github.io/server-side-tls/ssl-config-generat... [2] https://wiki.mozilla.org/Security/Guidelines/OpenSSH https://wiki.mozilla.org/Security/Guidelines/OpenSSH
- YouKnowBetter 9y agoGood point about the sshd_config generator. Who knows, people might even use it. As to the up to dateness of the Mozilla Guidelines: it is not. Just see the entry "UsePrivilegeSeparation sandbox" which has been deprecated since 7.5 [0] [0] https://www.openssh.com/txt/release-7.5 https://www.openssh.com/txt/release-7.5