From owner-freebsd-security@FreeBSD.ORG Wed Dec 2 17:51:05 2009 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 9864510656E4 for ; Wed, 2 Dec 2009 17:51:05 +0000 (UTC) (envelope-from julian@elischer.org) Received: from outR.internet-mail-service.net (outr.internet-mail-service.net [216.240.47.241]) by mx1.freebsd.org (Postfix) with ESMTP id 56A1A8FC21 for ; Wed, 2 Dec 2009 17:51:04 +0000 (UTC) Received: from idiom.com (mx0.idiom.com [216.240.32.160]) by out.internet-mail-service.net (Postfix) with ESMTP id 01828961CA; Wed, 2 Dec 2009 09:51:04 -0800 (PST) X-Client-Authorized: MaGic Cook1e X-Client-Authorized: MaGic Cook1e X-Client-Authorized: MaGic Cook1e X-Client-Authorized: MaGic Cook1e Received: from julian-mac.elischer.org (h-67-100-89-137.snfccasy.static.covad.net [67.100.89.137]) by idiom.com (Postfix) with ESMTP id 5616D2D6011; Wed, 2 Dec 2009 09:51:03 -0800 (PST) Message-ID: <4B16A90B.50807@elischer.org> Date: Wed, 02 Dec 2009 09:51:07 -0800 From: Julian Elischer User-Agent: Thunderbird 2.0.0.23 (Macintosh/20090812) MIME-Version: 1.0 To: Poul-Henning Kamp References: <18401.1259761888@critter.freebsd.dk> In-Reply-To: <18401.1259761888@critter.freebsd.dk> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Mailman-Approved-At: Wed, 02 Dec 2009 17:58:28 +0000 Cc: freebsd-security@freebsd.org, Mohd Fazli Azran Subject: Re: Increase in SSH attacks as of announcement of rtld bug X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 02 Dec 2009 17:51:05 -0000 Poul-Henning Kamp wrote: > In message <200912021324.nB2DOc58001138@lava.sentex.ca>, Mike Tancsa writes: >> At 07:51 AM 12/2/2009, Mohd Fazli Azran wrote: > >> The only way to deal with them I found [...] > > A very efficient measure: Move your sshd to another port number. > > You can configure the port in your .ssh/config file: > > Host foobar > port 122 > > so you don't have to remember it. > > I just use port knocking 99.999% of the time my ssh port is blocked by the firewall.