3 ms·
Do you actually run any public server with ssh on 22 and monitoring logs about it? From my experience noise on port 22 is so high that you wouldn't even notice
by hatch_q 6y ago
Do you actually run any public server with ssh on 22 and monitoring logs about it? From my experience noise on port 22 is so high that you wouldn't even notice actual targeted attempt.
- axegon_ 6y agoNo, I don't, but that has nothing to do with security and everything to do with routing. Noise is just as high on other ports so relying on moving a port or even a password is redundant as far as security is concerned. Personally I only have two servers which are publicly exposed to any form of ssh connections, both acting as access servers, nothing more. I've made several traps so if someone does manage to log in, I'll be immediately notified and I've also added a kill switch, so I can shut them down anytime with a click of a button.
- hatch_q 6y agoNoise is not high on other ports. Noise on mine (when i changed port from 22) went from 100+ attempted logins every hour to 1 per week.
- axegon_ 6y agoWell that's you, here's mine: > alex@srv002 ~ cat /var/log/auth.log | grep 'Disconnected\sfrom.*\[preauth' | wc -l > 432 All of those are from today...