Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If you're worried about ssh brute force or just don't like all the noise in your logs, moving the port tends to drop off about 95% of them. In addition, running iptables tarpit rules (or your OS equivalent) tends to kill the rest fairly quickly.


Annoyingly I did this once and then promptly forgot the port number, resulting in nmap time :(


I put info like this in a password manager for sanity (Keepass, I work on a PC).

One easy way to manage it is make a folder for each hostname, and add things like mysql root password, ssh port, public IP, pivate IP as different entries relating to the all aspects of managing the host.


Yes I use keepassx as well now :)


I've been using sshguard, but I like the sound of these.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: