4 ms·
No idea why you are being downvoted, this is a solid advice. Masscan [1] claims to scan whole IPv4 Internet for a single port in 5 minutes. Moving to a random h
by kees99 7y ago
No idea why you are being downvoted, this is a solid advice. Masscan [1] claims to scan whole IPv4 Internet for a single port in 5 minutes. Moving to a random high port would increase scan time 64000-fold, to 7 months.
You'd still be advised to disable password-based auth and/or configure fail2ban, though.
[1] https://github.com/robertdavidgraham/masscan https://github.com/robertdavidgraham/masscan
- parliament32 7y agoIt's a bad idea, privileged ports are a thing for a reason. https://www.w3.org/Daemon/User/Installation/PrivilegedPorts.html https://www.w3.org/Daemon/User/Installation/PrivilegedPorts.... https://adayinthelifeof.nl/2012/03/12/why-putting-ssh-on-another-port-than-22-is-bad-idea/ https://adayinthelifeof.nl/2012/03/12/why-putting-ssh-on-ano...
- kees99 7y agoYou have a point there, but it's far, far from being so clear-cut. Privileged ports is a measure to guarantee that daemon listening there was started with root privileges. Which is a useful guarantee on a shared server, less so on a single-purpose or personal server. Plus, if you have an sshd started at boot, and already listening on a pre-defined high port, there is very little chance another program could bind to the same port, save crashing and racing the daemon. Finally, in ssh protocol, server authenticates itself to the client, so even if by some trickery a bogus ssh server would bind to the same port, it will either need to access /etc/ssh/ssh_host_*_key, which are enforced to be root-readable only, or risk being trivially detected by a client comparing presented public key to that saved from last login in the ~/.ssh/known_hosts. There are also some DPI firewalls, or just port-based firewall that can block ssh traffic on a non-standard port, but assuming we are talking about your own server, that should be easy to rectify too.
- parliament32 7y agoYou understand the risks, but it's also a bad idea because it's effectively security-by-obscurity. I can port scan your host and find your SSH port in just a few minutes. Port knocking is better but still not foolproof unless you're doing some crazy 12-port sequence... And not having hordes of chinese bots hammering on our SSH port makes us slip up and do silly things like leaving password auth enabled. There's no harm in having connection attempts on your ssh port. Changing your port will not make you more secure against a dedicated attacker, and you just make things harder for yourself (and marginally less secure, for the reasons you mentioned) with no real benefit. And like I mentioned in the other comment, just use SSH keys and disable password auth. It's not hard, and it's all it takes to thwart every bot that hits you on port 22. If you want to be more hardcore you can run fail2ban or firewall the port down to your country or whatever. It's the equivalent of "I connect to my host via IP address instead of having DNS records because it'll be harder for them to find!".
- deleted 7y ago[deleted]
- demosthenex 7y agoObscurity is just one more security tactic. Security by obscurity as the only defense is bad. As an additional layer to many defenses it is a sound choice. You still paint camoflage on a tank.
- icedchai 7y agoThere's no harm in those attempts, but they are annoying. Even with fail2ban there is extra stuff running, unnecessary connections, junk in your logs. The benefits of moving SSH off 22 for your personal, internet facing servers outweigh the negatives.