5 ms·
But they don't scan every port. I've been running my SSH server on a non-standard port for a long time, it took four years until I had the first bot with login
by skrause 3y ago
But they don't scan every port. I've been running my SSH server on a non-standard port for a long time, it took four years until I had the first bot with login attempts. About a year ago I changed the port and haven't seen any bots since then.
- qwertox 3y agoYou can surround your custom port by a couple of ports on which a simple server listens for connection attempts. Any connection attempt is considered hostile and the ip will then be blacklisted in iptables. This prevents portscans from reaching your port.
- metadat 3y agoOnly works for sequential scans, most scanners are more targeted towards specific services.
- AlecSchueler 3y agoIf they're targetting SSH specifically how are they going to guess i'm running it on port 1690 and not port 22 other than by scanning up in sequence?
- kevindamm 3y agoDifferent quality of locks in the ever-escalating arms race. Probably there are many many more sequential scanners out there. For the persistent actors who are doing random ordering or shuffle then you could add port-knocking for the real sshd... but then they just have to find a working client and sniff the connection requests... to which you add a TOTP step for determining which ports to use, and so on...
- dambi0 3y agoThere is a known upper bound they could randomise the guesses from the range.
- yard2010 3y agoExcuse the old school metaphor - you put a lock on your door so your house is harder to break into, not to prevent anyone from breaking into your house.
- metadat 3y agoAbsolutely agree, when I wrote this I was thinking more of defending against the low hanging fruit - mass scanners. Once someone has deemed you a worthwhile target and is carefully proving all ports, these more nuanced approaches become more worthwhile. Even then, a sophisticated adversary may have many unique src IPs at their disposal.
- deleted 3y ago[deleted]