3 ms·
If you're worried about ssh brute force or just don't like all the noise in your logs, moving the port tends to drop off about 95% of them. In addition, runnin
by wildcard0 14y ago
If you're worried about ssh brute force or just don't like all the noise in your logs, moving the port tends to drop off about 95% of them. In addition, running iptables tarpit rules (or your OS equivalent) tends to kill the rest fairly quickly.
- meaty 14y agoAnnoyingly I did this once and then promptly forgot the port number, resulting in nmap time :(
- munger 14y agoI put info like this in a password manager for sanity (Keepass, I work on a PC). One easy way to manage it is make a folder for each hostname, and add things like mysql root password, ssh port, public IP, pivate IP as different entries relating to the all aspects of managing the host.
- meaty 14y agoYes I use keepassx as well now :)
- fusiongyro 14y agoI've been using sshguard, but I like the sound of these.