Leaving a door open?

From: Emmanuel Goldstein (goldstein101_at_gmail.com)
Date: 05/27/05

  • Next message: Andrew Shore: "RE: avoid using domain admin account installing programs"
    Date: Fri, 27 May 2005 08:02:37 +0200
    To: security-basics@securityfocus.com
    
    

    Hi!

    My ISP gives me a static Ip and I was thinking about leaving the SSH
    port open so I can access my computer from anywhere since i always
    have it switched on.

    I have a linux box that is integrated in my home Lan, and a router
    with firewall capabilities.

    Is this secure??? Note that my admin password is really hard to guess,
    so im not concerned about bruteforce attacks.

    Should I map ports so instead of opening 22 I access through (eg) 'ssh
    -p 7623'. That way is not that obvious i have an open ssh port is, it?

    Any other security issues i should be concerned about?
    Is this a good idea?
    Is it better to just set up an ftp server?

    Thanks for your help. Cheers. Bye.


  • Next message: Andrew Shore: "RE: avoid using domain admin account installing programs"

    Relevant Pages

    • Re: how to login port 22 with ssh behind a router.
      ... This prooves that forward and reverse name resolution also works fine on your home system. ... Therefore your problem is not with your home system settings, not with your ISP, and not with any firewall/gateway/router before you reach your data centre. ... If you run ssh with the -v option it might show you where the problem is. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Losing part of the Internet-connection, from time to time.
      ... I can use my Internet-connection just fine (everything works (www, ftp, ... ssh etc) and has normal speed). ... that my ISP get owerloaded between 7pm and 10pm? ... was a recent FCC case regarding this. ...
      (comp.security.firewalls)
    • Re: how to login port 22 with ssh behind a router.
      ... This prooves that forward and reverse name resolution also works fine on your home system. ... Therefore your problem is not with your home system settings, not with your ISP, and not with any firewall/gateway/router before you reach your data centre. ... If you run ssh with the -v option it might show you where the problem is. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Dynamic IP
      ... There are other ways to do this than with dynamic DNS, ... go "ssh user@$IP_ADDRESS", and Yo're done. ... Your ISP gave You, especially if it changes while You're not at home. ... dynamic DNS service), all services that Your box offers are available ...
      (comp.os.linux.networking)
    • Re: create inbound tunnel through firewall.
      ... > ssh) to that computer. ... local network. ... ISP, to know how to route to his RFC1918 address. ... While I do have a publicly reachable address to my firewall, ...
      (alt.os.linux)