Hacker News new | ask | show | jobs
by stephen_g 4618 days ago
Well, apparently with Zmap [1] you can do internet-wide scans in less than an hour from a single host, so I can't imagine they'd have that much trouble finding any open SSH ports on a smaller IP range.

So just changing the SSH port will do little, but enabling port knocking would help it stay hidden.

1. https://zmap.io/zmap-talk-sec13.pdf

1 comments

"Less than an hour" is with gigabit internet, which is rare for an attacker to have.
With a 100 Mbit/sec connection, that would become "Less than 10 hours". That's still quite fast.