Penetration Testing mailing list archives

Re: Some new SSH exploit script?


From: Larry Offley <lucullus () shaw ca>
Date: Tue, 06 Jun 2006 15:25:23 -0700

Michael Sierchio wrote:
Running a service on a non-standard port yields zero increase in
security.  That was my point.

I am curious what you base this statement on. As far as I am concerned anything that cuts down on threats helps. Would you consider port knocking as security through obscurity?.

Isn't all security when distilled just security through obscurity?
It is all about knowing, having or knowing how to not need the requirements to access said service or device.
It is all about raising the bar.
If a zero-day exploit comes out I'm going to be glad my real ssh access is not on the default port.

Larry Offley
http://security.offley.ca but there is almost nothing to see here yet.

------------------------------------------------------------------------------
This List Sponsored by: Cenzic

Concerned about Web Application Security? Why not go with the #1 solution - Cenzic, the only one to win the Analyst's Choice Award from eWeek. As attacks through web applications continue to rise, you need to proactively protect your applications from hackers. Cenzic has the most comprehensive solutions to meet your application security penetration testing and vulnerability management needs. You have an option to go with a managed service (Cenzic ClickToSecure) or an enterprise software (Cenzic Hailstorm). Download FREE whitepaper on how a managed service can help you: http://www.cenzic.com/news_events/wpappsec.php And, now for a limited time we can do a FREE audit for you to confirm your results from other product. Contact us at request () cenzic com for details.
------------------------------------------------------------------------------


Current thread: