5 ms·
If you close all the ports you do not use and properly configure all services that listen on the ports that you do use, should you care? Should you bother with
by wrx100 3y ago
If you close all the ports you do not use and properly configure all services that listen on the ports that you do use, should you care? Should you bother with black holing, port knockers, non-standard port or even firewalls for that matter? Honest question
- tsujamin 3y agoUse one of the dial-outward mesh VPNs or authenticating proxies (Tailscale, MS AppProxy, CF Tunnels etc), block all incoming traffic and stop caring all together imo
- jcrawfordor 3y agoProbably not. This kind of scanning is essentially nuisance behavior. Like any nuisance, you could ignore it, or you could take action to suppress it. Where you land on that is largely personal opinion, but for a commercial project you should probably lean towards "ignoring" since any action against tends to create the possibility of false positives that affect customers. For personal use, I do feel that Wireguard or managed Wireguard setups like Tailscale are so easy to use that putting everything behind a VPN is cheap insurance and even convenient, since it takes care of NAT traversal for you.
- bigiain 3y agoFor me at least, firewalls are worthwhile for "defence in depth". I may have closed off all services I'm not using, but a firewall will still help if I forget one or if I later accidentally start something that listens on a port. I also use blackholing (with fail2ban) and non standard ports (for ssh) - but just as a way to quiet down log files rather than ascribing much ion the way of security benefits to them.
- throw0101b 3y ago> I also use blackholing (with fail2ban) and non standard ports (for ssh) - but just as a way to quiet down log files rather than ascribing much ion the way of security benefits to them. Just switch to IPv6: good luck scanning a /64. :)
- bigiain 3y ago1999^h^h^h^h 2003^h^h^h^h 2017^h^h^h^h 2024 is the year of Linux^h^h^h^h^h IPv6 on the desktop. This time for sure! :-)
- throw0101b 3y ago> IPv6 on the desktop. I had IPv6 on my home desktop for several years before I switched ISPs a few months ago. My new ISP does not offer IPv6 on their residential network… but their mobile telco subsidiary gives it out to smartphones (IPv6-only). ¯\_(ツ)_/¯
- midasuni 3y agoI had linux on my desktop in all the years mentioned too 90% of desktops/laptops get a 192.168.0.x address. Maybe some do ipv6 as well
- 0xbadcafebee 3y agoFor "professional" stuff, yes, it matters. Cyber criminals follow patterns, starting with very low-effort trolling for new services without much defenses. Bots scan the internet for open services, enumerate them, and try to gain access. If they find some, they will use a tiny amount of effort to see if the target might be worth exploring. If it seems profitable, the cybercriminal will spend more effort on things like account enumeration, login brute force, scanning for commonly exploitable methods, phishing. The more they find, the more they're willing to invest in exploiting it. But a bot can perform a ransomware hijacking of a newly detected open service all on its own, so it doesn't take much. Simple mitigations can be very effective in holding back their interest. Captchas, rate limiters, error pages with no information leakage, block lists of low-reputation IPs, or outright blocks of countries you don't do business with. They make the difference between 50k login attempts per minute, or crickets. Don't use port knocking tho. It technically works, but is embarrassing, like a grown man in a trilby. Something else (like rate limiting combined with certificate auth) will be more effective and less weird.
- 0cf8612b2e1e 3y agoWhy the distaste for port knocking? It seems like it would reduce untargetted attacks to zero.
- IcePic 3y agoMy guess is that it is a sort of knee-jerk reaction. Just like the xkcd about CorrectBatteryHorseStaple, where there is a huge difference if the attacker knows for certain that everyones password is Four English Words From The Dictionary, or if you use those four words on a "anything 8 chars or longer works fine" system. If you know a site has a 4-words policy, the xkcd pw has very low entropy, but if you use this strategy on a "any pw goes" site, a bruteforcer would have to test all lengths upto 25 chars before finding yours (sort of). So in the port-knock case, it is probably a rather poor method in the specific case that I am on some remote network, and the evil 3rd party is actively sniffing my traffic from my client to my server and can record the knocks. If I have a simplistic knock sequence and they sniff it, they can replay it and get access to my https. But, if we are talking about some 3rd party that only knows a service may be up on the host newly.minted.cert.ccTLD, then it is FAR less likely that they can ALSO sniff my port knocking sequence and start abusing my new TLS service. The chances become almost ridiculously low for this to occur. So I agree that simplistic port knocking is sort of bad in the long run for cases like "I am often on a hostile network but still want to talk to my home server securely" but would work wonders for "soon after the cert is signed, someone scans my TLS boxes ip".
- DeathArrow 3y agoIn that case I think you should not be worried.