5 ms·
A high numbered port (above 1024) can be bound by non root programs. Use some non 22 port below 1024 if you want to change the port. Or use some RBAC system lik
by munin 8y ago
A high numbered port (above 1024) can be bound by non root programs. Use some non 22 port below 1024 if you want to change the port. Or use some RBAC system like selinux to keep anyone from binding to 2222 or whatever.
- gsich 8y agoWhat is the problem?
- nitrogen 8y agoAnother authorized user or a non-root RCE compromise could start listening on the ssh port if sshd ever dies for some reason.
- gsich 8y agoAnd then what? /etc/ssh is still owned by root, another user can't see the hostkeys. So you'll get an error message if custom keys are used.
- dredmorbius 8y agoRemote user tries to log in. Cannot. Issues (or trojan prompts for) password. It's a game of percentages.
- gsich 8y agoSSH key verification...
- dredmorbius 8y agoServer key? Sure, but what's the accept rate on new keys? On short-lived, poorly provisioned, AWS instaances, as just one example. Again, percentages. With enough attempts, some will succeed.
- gsich 8y agoIf it's a new server (like your example) there should be no other user already logged in. If it's not new, then you'll get a warning. And focusing on the "shortlived", so the damage is also shortlived... I can only speak for myself, if other people are ignoring warnings, it's their problem.
- dredmorbius 8y agoThe original question was: what's the risk, or threat model. I believe that's been adequately addressed.
- nitrogen 8y agoThe other question is whether other risks are greater; if a high port number is your only choice, or handled by port forwarding on a router, or you are the only user, or high numbers are scanned sufficiently less often, then maybe you still choose one.
- dredmorbius 8y agoQuite. Though, as you note, another question. Restricting the remote IP range is another option.
- gregmac 8y agoAwesome point, and exactly the advice I was looking for.