Skip to content

Comment on Simple SSH Securityparent

Comments

the vast vast majority of addresses aren't going to respond on port 22.

Lets say there's 2,000,000 IPv4 addresses that are being used on the internet.

If you scan 64,511 ports on each of them (65536-1024-1), that's still 129,022,000,000 connection attempts. Probably not worth it.

Doesn't help much when shodan has already portscanned everyone.

I just searched for "ssh -port:22" and found many hits.

But also yes. Switching port (or just blocking China) will vastly reduce SSH probes.

Don’t forget to block Brazil And Romania And Kazakhstan And …

I'm not saying there aren't non-China probe spam.

But without China it's just non-stop to the point of consuming noticeable amount of hard drive space for logs, and making it annoying to read logs looking for other things.

At least that's my experience.

Back in the EFNet days everyone with a lick of sense autobanned all of Eastern Europe, Asia, and South America. It was literally nothing but script kiddies.

Any decent firewall can do geo location allow. I block all but specific counties. Can't trust Christmas Island....

Last time I looked at the IPs spamming my websites, a lot of them were from Europe, surprisingly.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.