4 ms·
> I do hope one takes the vigilance to set a port number sufficiently high up, and sufficiently random looking Hopefully not over port 1023. If a user gets on
by cd34 14y ago
> I do hope one takes the vigilance to set a port number sufficiently high up, and sufficiently random looking
Hopefully not over port 1023. If a user gets on the system and crashes your ssh daemon through OOM killer or one of many other methods, that non-root user can then restart its own daemon and listen to that port that you put >1023 'for security reasons'.
Accidentally answering yes when it says a new key was detected is all it takes to get keylogged.
- Dylan16807 14y agoI don't see how you could answer yes to that prompt without realizing it was the 'key has changed' prompt. Especially when half the ssh clients I've seen abort entirely when the key changes.