Re: What can I do about breakin attempts?
- From: ibuprofin@xxxxxxxxxxxxxxxxxxxxxx (Moe Trin)
- Date: Sun, 26 Feb 2006 18:15:40 -0600
On Sun, 26 Feb 2006, in the Usenet newsgroup comp.os.linux.security, in article
<20060226042451.11f5899a@xxxxxxxxxxxx>, Ertugrul Soeylemez wrote:
ibuprofin@xxxxxxxxxxxxxxxxxxxxxx (Moe Trin) (06-02-25 14:23:48):
Why is your server accepting connections from the world? Use your
firewall to restrict access to the limited number of addresses (or
address ranges) where you might actually want to connect. Another
tact is to move the server to a non-standard port.
I don't really get why nobody here has ever heard anything about
key-based authentication. It makes brute-force attacks practically
impossible.
As Larry Wall likes to say "There's more than one way to do it."
By restricting the allowed IP addresses, and/or moving the service to
an uncommon port number, I don't see these attempts. The bottom line
answer is "what works for you".
You (Moe) seem to be particularly interested in cryptography. I
expected that _you_ would be the first to recommend that.
I'm a networking guy, not a crypto student. Blocking/moving comes to my
mind as the quickest solution. There is nothing to prevent combining
these techniques, nor is there much in choice of one over the other.
Actually, what I'm looking at right now is a port-knocking solution as
an alternative to restricting the IP range, though still using random
destination port numbers.
Old guy
.
- Follow-Ups:
- Re: What can I do about breakin attempts?
- From: Ertugrul Soeylemez
- Re: What can I do about breakin attempts?
- References:
- What can I do about breakin attempts?
- From: Chris
- Re: What can I do about breakin attempts?
- From: Moe Trin
- Re: What can I do about breakin attempts?
- From: Ertugrul Soeylemez
- What can I do about breakin attempts?
- Prev by Date: Re: Dictionary attacks on port 22
- Next by Date: Re: pop3 through ssh tunneling
- Previous by thread: Re: What can I do about breakin attempts?
- Next by thread: Re: What can I do about breakin attempts?
- Index(es):
Relevant Pages
|