Re: SSHD: Limit login attempt rate



On Fri, 25 Jul 2008 05:45:08 -0700, bmearns wrote:

This is
also my main reason for not moving the server to another port: I need to
be able to access it from a handful of networks that lock down all but
standard ports (i.e., from within these networks, you can't connect to
remote hosts on ports other than, say, 80, 8080, 22, and maybe a few
others), so I'm not clear on how port knocking would be any different in
this aspect?

There are some fun variations on port knocking. For example, what about
a login-protected https:// URL? A connection there causes the iptables
entry that opens the port to the transmitting URL. The down side is that
a forced web proxy can mess with this, esp. if the sender is in RFC1918
address space.

Another is eavesdropping (via logging to syslog which is directed to a
pipe that a daemon is reading) on the query stream of a DNS server. The
proper query from a given IP opens SSH access to that IP. This only
works if the sending computer is permitted to make DNS requests directly
(as opposed to via separate resolvers).

- Andrew
.



Relevant Pages

  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)
  • Re: Companyweb + Clients firewalls
    ... and connect up to your server and avoid going ... does not work i.e. from within customer network/firewall. ... port 444 but allows 443 as we can access owa, ... This is something that whomever manages these networks will have to deal ...
    (microsoft.public.windows.server.sbs)
  • Re: SRV RRs support in Internet Explorer?
    ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
    (microsoft.public.win2000.dns)
  • Re: Still cant connect to RWW or OWA remotely
    ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
    (microsoft.public.windows.server.sbs)
  • Re: cannot send mail from Windows mail
    ... When a username/password combination doesn't work in Windows Mail, ... I mean I dont use it but as outgoing address for my ISP account. ... youir username and password are correct for your mail server". ... Ask your home ISP if they support SMTP on a port other than 25. ...
    (microsoft.public.windows.vista.mail)