Mailing Lists: Apple Mailing Lists

Image of Mac OS face in stamp
 
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Is port 22 safe for SSH through firewall?



On Mar 14, 2007, at 10:04 AM, Dan Shoop wrote:

At 9:18 AM -0700 3/14/07, Dominic Lepiane wrote:
Content-Type: multipart/signed; boundary="nextPart19268106.kXOfB6aYL2";
protocol="application/pgp-signature"; micalg=pgp-sha1
Content-Transfer-Encoding: 7bit


There's consequences no matter what course of action you take. I would say
generally SSH is a secure service (assuming you update your server regularly)
but be aware:


a) SSH scans/probes are very common right now. Accounts with very bad
passwords may get compromised by these worms. Moving to a non- standard port
would circumvent this.

Not really. You just disguised the port but any smart attacker will notice the service running on another port and switch to targeting that.

FWIW, in our case, port 22 is swamped with "unsmart" attackers, to the tune of 100s per minute, 24/7, making for logs too unwieldy to even peruse. If we changed the port number, it would have the benefit of reducing the noise level by 90%, and getting just the "smart" attackers in the log.


I've tried a few "change port 22 how-tos", such as on MacOSX Hints, but I've not found a procedure explained well enough that I could get to work. (OSXS 10.4.9 PPC 2x2GHz G5)

Roland


_______________________________________________ Do not post admin requests to the list. They will be ignored. Macos-x-server mailing list (email@hidden) Help/Unsubscribe/Update your Subscription: http://lists.apple.com/mailman/options/macos-x-server/email@hidden

This email sent to email@hidden
References: 
 >Re: Is port 22 safe for SSH through firewall? (From: Adam Gerson <email@hidden>)
 >Re: Is port 22 safe for SSH through firewall? (From: Dominic Lepiane <email@hidden>)
 >Re: Is port 22 safe for SSH through firewall? (From: Dan Shoop <email@hidden>)



Visit the Apple Store online or at retail locations.
1-800-MY-APPLE

Contact Apple | Terms of Use | Privacy Policy

Copyright © 2007 Apple Inc. All rights reserved.