Goodbye SSH Brute-force!

Principal Research & Translation Specialist at ST Engineering Info-Security Pte Ltd
Search for a command to run...

Principal Research & Translation Specialist at ST Engineering Info-Security Pte Ltd
Extra fun, put this: https://github.com/skeeto/endlessh on the standard port... It keeps SSH clients locked up for hours or even days at a time.
Why bother? I wrote four entries related to Cyber Deception, submitted March 2021, yet none are found on Google with the exact title search. Instead, the Cyber-Observatory & Hackernoon versions (same titles & contents) came out on Google-search first...

Recap Part 1 introduced three phases of Cyber Deception Campaign & highlighted 4 considerations related to Industrial Networks: (1) Safety, (2) Availability, (3) Realism, & depending on our strategic goals, (4) Secrecy that we should be mindful thro...

Recap Part 2 of this series touched on planning & measuring success of a Cyber Deception campaign. It also covered some "estimations" of Threat Actors based on Operational Security abilities. This part will illustrate more examples of simulation vs d...

Recap Part 1 introduced 3 Phases of Cyber Deception Campaign. We briefly highlighted 4 considerations related to Industrial networks: (1) Safety, (2) Availability, (3) Realism, & depending on our strategic goals, (4) Secrecy that we should be mindfu...

Introduction This series is about Knowing ourselves, our enemy & plan in a way to conjure "grounds" & "weather" to our advantage. This approach is adapted from a joint-paper by Mohammed H. Almeshekah and Eugene H. Spafford, published by Springer ...

sshd to listen with private IP 
When we disrupt one or more of the Necessary & Sufficient conditions for any Cyber-Physical attacks, in this case Threat Accessibility, we lower the risk ( probability). This applies to other administrative service/ports.
Even if there were a 0-day ssh-server vulnerability that is exploitable, attackers will need to first get into your client.
Enabling Multi-Factor/Step Authentication on your VPS provider is also related to Threat Accessibility.
Server-logs are useful for investigating any incidents. When cluttered with blocked/refused SSH attempts, those entries are simply "noise", which will be eliminated after this configuration.
Why waste it on "noise"?