|
|
|
|
|
by freeqaz
1583 days ago
|
|
Surprisingly, just changing the port is highly effective. Scanning every ipv4 address still chews bandwidth even for just a handful of ports. Add ipv6 into the mix and it's straight up infeasible to scan for even ONE port on every host! Port knocking + key auth + non-default port is pretty damn good security, even against zero days in SSH. |
|