Re: What can I do about breakin attempts?



ibuprofin@xxxxxxxxxxxxxxxxxxxxxx (Moe Trin) (06-02-26 18:15:40):

By restricting the allowed IP addresses, and/or moving the service to
an uncommon port number, I don't see these attempts. The bottom line
answer is "what works for you".

I'm a networking guy, not a crypto student. Blocking/moving comes to
my mind as the quickest solution. There is nothing to prevent
combining these techniques, nor is there much in choice of one over
the other. Actually, what I'm looking at right now is a port-knocking
solution as an alternative to restricting the IP range, though still
using random destination port numbers.

Still, isn't it much better to make brute-forcing (practically)
impossible? If you're a network guy, then you should know that keys are
not just more secure, but also much easier to manage/handle; one single
key for every machine you want to connect to -- without security risks.

However, your non-standard port approach will keep arbitrary
script-kiddies away, but not a 'real' attacker. He will find the port,
and he will also discover your knockd secret, if he has some good reason
to break into your system.


Regards.
.



Relevant Pages

  • Re: oops again
    ... If you leave your car at the mall with the keys ... >> networking from your server on up can you determine this. ... >> You configure the Firewall on the Router to just block every single port. ...
    (microsoft.public.inetserver.iis)
  • Re: Enhanced Remote Desktop Web Connection Page
    ... To download a modified client, ... the advanced client on the bottom of the list... ... My Networking Blog: http://www.networkblog.net ... >I've been frustrated by the inability to put the port number in on the ...
    (microsoft.public.windowsxp.work_remotely)
  • Re: Ethernet for MegaSTe
    ... network access) every time I needed to use the floppy drive, ... if you can get a NetUSBee you can have Sting/MintNet networking ... takes 30 minutes to transfer a few files from the MegaSTe to the Mac ... If you really cant get rid of the stuff in the cartridge port and get ...
    (comp.sys.atari.st)
  • Re: Remote Desktop Web Connection
    ... Can you telnet the port? ... Networking, Internet, Routing, VPN Troubleshooting on ... How to Setup Windows, Network, VPN & Remote Access on ...
    (microsoft.public.windowsxp.work_remotely)
  • Printing from Word
    ... I have had continuous problems printing from an XP to a printer connected to ... this may be a networking problem, I would like to know what Word ... toTCPIP, the system tries a network connection to remote IP port 445, ... WinXP keeps trying for some time or number ...
    (microsoft.public.word.newusers)