3 ms·
Well, since you outright said I was wrong... > It's almost always a good idea to change ssh to a high-port [citation needed] > QoS is irrelevant to most You
by ohboyacomment 14y ago
Well, since you outright said I was wrong...
> It's almost always a good idea to change ssh to a high-port
[citation needed]
> QoS is irrelevant to most
You sure? QoS is even in consumer routers these days. I'm speaking from experience, and have shown a 20% drop in scp performance by moving away from 22 on a consumer Netgear. This point really isn't worth caring about, though, but...
> bots do not scan !=22
I run a honeypot on 2222 with a well-known address. It's been scanned by 47 bots (out of 1,449 against 22) in the last 48 hours. They're out there, because it's not exactly a secret that administrators move SSH. APTs will scan every single port looking for OpenSSH, because it announces itself in the opening conversation. Granted, they are a smaller figure, but your assertion does not hold water.
You are also building upon obscurity. Ports are just endpoints. If you shuffle five feet to the left, you're still very likely standing in the same room. Your system is secure with SSH on 22. Period.
> if an attacker can launch daemons on your server then you've already lost anyway
You didn't read what I wrote carefully. I did not say attacker.
Ports under 1024 are reserved for root. Unless you are UID 0, you cannot bind to a port below 1024. That's why SSH is, by default, on 22. That is a service that only root should be able to start.
If you move it to 2222, say, inside a company of a bunch of employees, one day I might get clever after your sshd crashes or I somehow coerce it to crash (and there are ways). Now there is nothing listening on 2222, but I have a physical console, and I launch my own trojan sshd on 2222 (totally legal, because I can bind to 2222) and capture passwords from everyone that connects. Now I have passwords from all of my fellow employees, and I can start trying other systems.
That party is not an attacker. He is an employee that you gave an account. And do you have monitoring checking that the sshd listening on 2222 is running as root? Didn't think so.
Ports above 1024 subvert the security model of Unix, and should not be used for a system-critical service. Ever. If you are going to move it even against this advice, do not go above 1023.
That being said, I'd like you to provide one good security reason to move SSH to a separate port. To be honest, this whole "move SSH to a high port" is a complete and utter lie started by someone and parroted by every administrator who heard it from another guy, and it is rooted in absolutely nothing. It's not my job, as you've demanded, to justify leaving SSH at 22. It's your job to justify moving it.
- moe 14y agoIt's getting a little painful so I'll keep it short; the point of moving the port is to have a time-window to respond when a ssh pre-auth exploit is discovered (since automated bots don't hit your daemon when it's on a high-port). The rest of your comment (faith in privileged ports, hollywood attack) doesn't lend much credibility to your advice.
- danielweber 14y agoObscurity is a fine wrench in your toolbox of security. You shouldn't depend on it, but being a bit out of the way means you have less people rattling your doorknob.