Hacker News new | ask | show | jobs
by akerl_ 3161 days ago
Gotcha. All valid points, and I’m a big fan of firewall-based port rerouting like you describe.

I agree that an attacker who gets code exec on an app server is in a pretty fun spot already, and has a lot of different paths to escalate/persist/etc that don’t involve misuse of your ssh daemons port.