Re: Need urgent help regarding security

ray_at_redshift.com
Date: 11/21/05

  • Next message: ray_at_redshift.com: "Re: Need urgent help regarding security"
    Date: Mon, 21 Nov 2005 04:30:04 -0800
    To: Marian Hettwer <MH@kernel32.de>
    
    

    At 09:33 AM 11/21/2005 +0100, Marian Hettwer wrote:
    | Hi there,
    |
    | ray@redshift.com wrote:
    | >
    | > Also, if you have access to the router, it's handy to re-write traffic from a
    | > higher public port down to port 22 on the server, since that will trip up
    anyone
    | > doing scans looking for a connect on port 22 across a large number of IP's.
    | >
    | No. That's security by obscurity and doesn't make your system even a wee
    | bit more secure.
    | Disable root login via ssh (like already mentioned), enforce public-key
    | authentication and maybe even go with OPIE.
    |
    | > Anyway, just a couple of ideas I thought might be helpful while on the subject
    | > of SSH hardening :-)
    | >
    | all of them were about hardening, except the security by obscurity
    | "put-the-sshd-on-another-port" advice ;)
    | don't do that.
    |
    | Regards,
    | Marian

    Okay, I'll give you that. However, if someone was only scanning port 22, then
    it would help keep you out of the scan :)

    Ray

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: ray_at_redshift.com: "Re: Need urgent help regarding security"

    Relevant Pages

    • RE: Re: Concepts: Security and Obscurity
      ... so long as you understand that the server location and port number ... security in the slightest." ... Beale's assertion that "Obscurity Potentially Slows Down the Attacker". ... BDO Kendalls is a national association of separate partnerships and entities. ...
      (Security-Basics)
    • RE: Re: Concepts: Security and Obscurity
      ... BDO Kendalls is a national association of separate partnerships and entities. ... last I heard availability had something to do with security. ... Maybe we can all agree that "port obscurity" is a special case of STO. ...
      (Security-Basics)
    • Re: Re: Concepts: Security and Obscurity
      ... Then you must admit port obscurity is a special case, ... BDO Kendalls is a national association of separate partnerships and entities. ... Subject: Concepts: Security and Obscurity ...
      (Security-Basics)
    • RE: Re: Concepts: Security and Obscurity
      ... This is not obscurity for security - rather a use of a different port ... Subject: Concepts: Security and Obscurity ... Security is based on risk management and ...
      (Security-Basics)
    • Re: Re: Concepts: Security and Obscurity
      ... server was on port 22 I received about 50-100 false logins per day. ... Subject: Concepts: Security and Obscurity ... TCP 2967 ... Put a server on any other port, and your number of attacks is going to be demonstrably lower than the numbers above. ...
      (Security-Basics)