Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Setting Up Your VPS with Gemini CLI or Claude Code

13»

Comments

  • forestforest Member
    edited April 16

    @artxs said: The idea of tying service "legitimacy" to a port number is a boomer's game that should've died long ago.

    I agree, but unfortunately we live in a world where people do click through warnings.

    And when the port you're trying to bind to is in the ephemeral range (and isn't set to reserved), sshd may not start even if there's no attacker in the equation at all. That alone is a reason not to use TCP/34221.

    Besides that, the only other issues are unlikely and contrived:

    1. Denial of service from a local attacker
    2. MITM by local process after side-channel attack obtaining host keys
    3. Pre-auth RCE against clients (quite rare)

    I agree that the primary purpose of making low ports privileged is no longer relevant as we no longer run things on massive shared servers with HTTP on port 80 and a bunch of untrusted users with personal sites on domain/~username/ and shell accounts, but that doesn't mean that binding SSH to port 34221 is smart or doesn't have security issues.

Sign In or Register to comment.