Re: Possible New Security Tool For FreeBSD, Need Your Help.

From: Nonya (nonya@virgin.net)
Date: 09/03/01


From: "Nonya" <nonya@virgin.net>
To: "Not Going to Tell You" <luckywolf19@hotmail.com>, <security@freebsd.org>
Date: Mon, 3 Sep 2001 15:53:51 +0100


>
> I have 240 boxes running sshd and restricted to our IP address on the
> Internet. We just want to hide the sshd port until we need it.
<snip>
>But by hidding the sshd port,
> maybe, just maybe, we can reduce the number of script kiddies from trying
> sshd scripts.

Running sshd on a non-standard port would probably have a similar effect,
especialy if you choose a port not included in nmaps default scans.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Change default ssh port
    ... > What is the best and secure method to change the default sshd port? ... 'sshd -p xx' ehere xx is the portnumber you want to use, ...
    (alt.os.linux.suse)
  • Re: starting ssh from inetd
    ... which tends to enhance security. ... >security hole in a particular implementation of inetd, ... Are you saying sshd is insecure when running stand alone and that it ... running sshd through inetd does not simplify the programming ...
    (comp.security.ssh)
  • Re: FreeBSD Security Advisory FreeBSD-SA-03:12.openssh
    ... > 99% of even the most heavily loaded servers have more than enough ... similar to sysutils/comconsole which reconfigures the shipping sshd to ... run under inetd so that others can benefit from your approach. ... Not to dismiss the idea of running sshd from inetd out of hand, ...
    (FreeBSD-Security)
  • Re: inetd[860]: ssh/tcp: bind: Address already in use
    ... Running sshd out of inetd is weird and unnatural, ... just comment out the ssh line in inetd.conf and restart the inetd ...
    (freebsd-questions)
  • Re: Possible New Security Tool For FreeBSD, Need Your Help.
    ... We just want to hide the sshd port until we need it. ... > Since we are also running sshd and IP ... Even then, if you set up a VPN, you can control access by domain or by ... a VPN client gets an address from your local address pool. ...
    (FreeBSD-Security)