Re: block_ssh_guessers



Lawrence D'Oliveiro wrote:

In article <oJ92g.4243$mu2.1615@xxxxxxxxxxxxxxxxxxxxxxxxxx>,
Bill Davidsen <davidsen@xxxxxxx> wrote:

Lawrence D'Oliveiro wrote:
In article <slrne47ssp.18i.ibuprofin@xxxxxxxxxxxxxxxxx>,
ibuprofin@xxxxxxxxxxxxxxxxxxxxxx (Moe Trin) wrote:

If you absolutely MUST allow connections from the world, and you can't
be bothered to set up certificates, google for port knocking.

port-knocking--don't be bloody stupid.

Care to share why you think port-knocking is stupid?

Ever heard of the term "replay attack"?

Ever hear of changing the sequence with each connection? As soon as the
sequence is used, it's changed, you can replay (IF that is, you were ever
able to get the sequence in the first place) all you want, the code you
sniffed is invalid.

Ever learn to think?
.



Relevant Pages

  • Re: block_ssh_guessers
    ... port-knocking--don't be bloody stupid. ... Ever heard of the term "replay attack"? ... Ever hear of changing the sequence with each connection? ... What happens if somebody else uses the sequence first? ...
    (comp.os.linux.security)
  • Re: SPECS A27 + M27 Portsmouth
    ... Steve Firth wrote: ... Because it's your life and despite the bloody stupid UK victim ... culture you have a great deal of responsibility for taking care of ... the laws of natural stuipidity take care of it all by themselves. ...
    (uk.rec.driving)
  • Re: SPECS A27 + M27 Portsmouth
    ... Because it's your life and despite the bloody stupid UK victim culture ... you have a great deal of responsibility for taking care of your own ... the laws of natural stuipidity take care of it all by themselves. ...
    (uk.rec.driving)
  • Re: block_ssh_guessers
    ... can't be bothered to set up certificates, google for port knocking. ... port-knocking--don't be bloody stupid. ... Ever hear of changing the sequence with each connection? ... then login WITH the right login or get locked out. ...
    (comp.os.linux.security)
  • RE: Beginner questions about backup/restore
    ... 821511 How to Replay Log Files That Have Been Generated Since the Last Full ... as long as the sequence is contiguous; ... Please do not send email directly to this alias. ...
    (microsoft.public.exchange2000.admin)