Похожие чаты

Hii! How do you handle ssh on production servers? We have

gone through the standard hardening steps(disable root/password login, listen on some other port, firewall configuration etc) but I am wondering if there is more I can do.

One idea I have is to make all the production servers part of the work VPN and have sshd listen only on the work VPN interface. work VPN is implemented using wireguard so extending it to production servers and keeping everything updated will be bit of a pain so I don't know if this is a good idea..

3 ответов

19 просмотров

This is already some good standard to be honest. You could provide the server with a fake SSH access on port 22, so people/bots that attempt would not care to explore further ports. And luckily nmap only reports common ports functions. If you run ssh on e.g. port 80, nmap will report it as "web/HTTP" stuff

for the legacy systems we use a bastion server that's only accessible via VPN

There is also https://en.wikipedia.org/wiki/Port_knocking, so you can hide the ssh port (even on a non-standard port)

Похожие вопросы

Обсуждают сегодня

Господа, а что сейчас вообще с рынком труда на делфи происходит? Какова ситуация?
Rꙮman Yankꙮvsky
29
А вообще, что может смущать в самой Julia - бы сказал, что нет единого стандартного подхода по многим моментам, поэтому многое выглядит как "хаки" и произвол. Короче говоря, с...
Viktor G.
2
@Benzenoid can you tell me the easiest, and safest way to bu.y HEX now?
Živa Žena
20
This is a question from my wife who make a fortune with memes 😂😂 About the Migration and Tokens: 1. How will the old tokens be migrated to the new $LGCYX network? What is th...
🍿 °anton°
2
30500 за редактор? )
Владимир
47
а через ESC-код ?
Alexey Kulakov
29
What is the Dex situation? Agora team started with the Pnetwork for their dex which helped them both with integration. It’s completed but as you can see from the Pnetwork ann...
Ben
1
Гайс, вопрос для разносторонее развитых: читаю стрим с юарта, нада выделять с него фреймы с определенной структурой, если ли чо готовое, или долбаться с ринг буффером? нада у...
Vitaly
9
Anyone knows where there are some instructions or discort about failed bridge transactions ?
Jochem
21
@lozuk how do I get my phex copies of my ehex from a atomic wallet, to move to my rabby?
Justfrontin 👀
11
Карта сайта