Re: Change SSH port? why does this seem to be safer?

From: Christopher Browne (cbbrowne_at_acm.org)
Date: 08/30/05


Date: Tue, 30 Aug 2005 04:53:52 GMT


> So can anyone tell my why changing a port number improves safety?

Ah, well, if you combine it with portsentry, you can make it unlikely
that someone can discover which port SSH is running on before they get
blocked.

Supposing I run ssh on port 7588 (picked at random), that means that
the only way for someone to *find* port 7588 is by searching ports at
random.

I also run portsentry, which blocks out IPs that try to do port scans.
Once a host has scanned a few ports, that host gets added to my
blacklist.

The chances of someone hitting port 7588 before getting blacklisted
are extremely poor.

-- 
(reverse (concatenate 'string "moc.liamg" "@" "enworbbc"))
http://cbbrowne.com/info/
If we were meant to fly, we wouldn't keep losing our luggage.


Relevant Pages

  • Re: portsentry
    ... One of the main problems with portsentry on Linux (or any other OS ... The program starts fine but when I do a port scan on the ... > # but not drop the route. ...
    (Focus-IDS)
  • portsentry
    ... I am trying to set up portsentry on redhat enterprise AS. ... the source correctly and edited the configuration file according to the ... The program starts fine but when I do a port scan on the ... # host when an attack is detected. ...
    (Focus-IDS)
  • Re: firewall: black or white...
    ... > There is one thing I however noted when using PortSentry. ... I got most of this when port 135 was bound ... At the end of the day, a properly configured firewall that performs ... effective ingress and egress filtering and is allowed to log effectively ...
    (comp.os.linux.security)
  • Re: firewall: black or white...
    ... >> If someone is looking for a system to attack, ... PortSentry is most likely the way to go. ... Works like a charm to stop most port scans and attacks ... This style of setup works great ...
    (comp.os.linux.security)
  • Re: Back Orifice - RedHat 7 [Update]
    ... I personally don't use portsentry, ... up on nmap). ... changed and there's something listening which shouldn't be. ... > know...bo2k on port 54320...just as you suggested. ...
    (comp.os.linux.security)