Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just changing the SSH port is probably enough for small VPS.

Port 22 is getting perma-DDOSed on public IPv4 addresses so use it at your own peril but at least for now most bots don't bother port scanning everyone.



Yup, in my experience moving the SSH server to any port other that 22 drops to zero the number of failed login attempts to VPSs last time I've checked.


Definitely not zero.. your server gets IPv4 port scanned 2-10 times a day.

CriminialIP, PaloAlto, Shodan, Stretchoid, Techties, Censy, Onyphe, VisionHeight, Internet-measurement, Infrawatch, BinaryEdge, and a bunch of Alibaba Cloud/Digital Ocean/VPN/Tor exit IPs all know which port your SSH server is on.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: