Mailinglist Archive: opensuse (1986 mails)
| < Previous | Next > |
Re: [opensuse] Results of moving ssh to a high port - Zero script kiddies in a 24 hour period.
- From: "David C. Rankin" <drankinatty@xxxxxxxxxxxxxxxxxx>
- Date: Thu, 27 Nov 2008 09:03:29 -0600
- Message-id: <492EB6C1.2030200@xxxxxxxxxxxxxxxxxx>
James Knott wrote:
That seems like it is next up on my learning agenda. I already use
ssh-key authentication, I guess I just need to turn password checking off.
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx
David C. Rankin wrote:
Listmates,
Moving ssh to a high port has been a resounding success at completely
eliminating the dictionary attacks against my server. And so far, I have not
had one single instance since making the change. I don't have any great
statistics, but I do have one that shows the impact very clearly. The number
of
log entries per 24 hour period before and after.
One thing you can do, to stop dictionary attacks, is use a key, rather
than password for access. No amount of password guessing will get
through if no passwords are accepted.
That seems like it is next up on my learning agenda. I already use
ssh-key authentication, I guess I just need to turn password checking off.
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx
| < Previous | Next > |