Communities

Writing
Writing
Codidact Meta
Codidact Meta
The Great Outdoors
The Great Outdoors
Photography & Video
Photography & Video
Scientific Speculation
Scientific Speculation
Cooking
Cooking
Electrical Engineering
Electrical Engineering
Judaism
Judaism
Languages & Linguistics
Languages & Linguistics
Software Development
Software Development
Mathematics
Mathematics
Christianity
Christianity
Code Golf
Code Golf
Music
Music
Physics
Physics
Linux Systems
Linux Systems
Power Users
Power Users
Tabletop RPGs
Tabletop RPGs
Community Proposals
Community Proposals
tag:snake search within a tag
answers:0 unanswered questions
user:xxxx search by author id
score:0.5 posts with 0.5+ score
"snake oil" exact phrase
votes:4 posts with 4+ votes
created:<1w created < 1 week ago
post_type:xxxx type of post
Search help
Notifications
Mark all as read See all your notifications »
Q&A

Welcome to the Power Users community on Codidact!

Power Users is a Q&A site for questions about the usage of computer software and hardware. We are still a small site and would like to grow, so please consider joining our community. We are looking forward to your questions and answers; they are the building blocks of a repository of knowledge we are building together.

What is the main reason for some website hosting companies to change ports?

+2
−4

Some website hosting companies change port 22 to some other open port.

I don't think that information security is the main reason to do that; first, because many hosting companies would explicitly state the alternative port in their documentation and second, because port scanners could generally find any alternative port.

Perhaps the main reason is that a small or starting website hosting company can have a non-virtual-computer-system with, say, two virtual-computer-systems, one with port 22 and one with port X as that allows them to save in equipment, otherwise, why doing it?

History
Why does this post require attention from curators or moderators?
You might want to add some details to your flag.
Why should this post be closed?

0 comment threads

1 answer

+2
−0

Many automated scanners will attempts brute forcing SSH servers running on port 22 using common username+password pairs. This is relatively easy. You just have to pick an IP range and you have as many ports to test as there are IPs in the range (one port per IP).

Change the SSH port to a different one and now there are thousands of ports to test per IP in that same range. This makes this type of attack unfeasible. Finding an open SSH port on a particular host is relatively easy, but if you're attempting to brute force thousands of hosts it may not be worth it. There are many easier targets.

History
Why does this post require attention from curators or moderators?
You might want to add some details to your flag.

0 comment threads

Sign up to answer this question »