Root Access Daily
Root Access Daily
@RootAccessDaily

Stop hardening SSH the dumb way

Stop hardening SSH the dumb way

Moving SSH to port 2222 stops zero serious attackers and breaks your tooling. Do the two things that actually matter:

— PasswordAuthentication no (keys only, full stop)
— AllowUsers deploy (whitelist one user, root login dies)

Then put the box behind a firewall that only allows SSH from your IP: ufw allow from 1.2.3.4 to any port 22. That's it. Brute-force traffic literally can't reach the daemon. Skip the port-knocking cosplay. Try it tonight.
Этот пост опубликован в Telegram-канале Root Access Daily. Подписаться можно по ссылке: @RootAccessDaily.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.