[H-GEN] brute-force ssh(s) attacks [Was: Installing a website!]

David Harrison trogspam at games.telstra.com
Tue Aug 9 21:36:16 EDT 2005


> Personally I'm not a fan of changing the port.

I'm generally not either, but we find that a lot of our servers get 
randomly probed on 22 just to see if sshd is listening, then we 
inevitably see a number of brute force attempts to try and log in.

Changing it to rand() seems to stop most of these random driveby style 
of attacks. Its not going to help that much for determined hack attempts 
but it certainly seems to stop our log files from filling up with 
connection attempts!

-- dave





More information about the General mailing list