TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

How to Hide AWS EC2 Instances from Network Scanning Bots Using IPv6

3 pointsby pawurbover 5 years ago

1 comment

parliament32over 5 years ago
Security through obscurity is generally a bad idea. The author proposes using ipv6 addresses because... the address is harder to guess? They don&#x27;t want to patch vulns so they&#x27;re scared of being scanned?<p>You shouldn&#x27;t be using password auth in a public-facing ssh server anyway (use keys!) but if you are, fail2ban is good for locking out brute force attempts. You can also use iptables to restrict access to just certain IPs&#x2F;subnets. Alternatively, run your own mesh VPN with tinc and configure sshd to only listen on the vpn address (this is the best solution).<p>Non-standard ssh ports are also an option, but keep in mind using unprivileged ports (&gt;1024) opens other attack vectors so you probably shouldn&#x27;t.
评论 #21456200 未加载