ssh on other ports

CrucialCarl

Junior Member
Feb 27, 2003
19
0
0
So.. I have a typical boring desk job. I sit here nearly all day and have hardly anything to keep me occupied. I rely on forums and news pages to entertain me. Up until recently, I had a ssh connection to my home computer where i could run AIM, ICQ and IRC.

Somebody was snooping around and asked our facility manager about the 'outside connection' coming from our building. He didnt know, but to be safe, i'm avoiding opening my shell today.

The question is, I am planning on changing my ssh configuration to run on port 80 (currently 22), or something less suspicious. Are there any downsides to this, and what is the best port to use?


 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
There shouldn't be any downside to doing so, other than possibly getting in trouble for using it. Don't use it if you aren't supposed to.
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
CrucialCarl, if some admin has the technical capability to see what TCP port you're using, they probably have the techncial capability to inspect the payload and will be able to figure out what you're doing quickly. If your employer's policy would forbid you from doing what you're doing, don't do it.

If this is just an admin being fascist, then why change? Just make sure your boss will smack 'em.

Of course, most admins who are clueful enough to sniff & inspect app data to find out what people are doing are also clueful enough not to care too much about users using SSH.
 

eigen

Diamond Member
Nov 19, 2003
4,000
1
0
Exactly how would the admin inspect the payload on a ssh connection?
 

cmetz

Platinum Member
Nov 13, 2001
2,296
0
0
eigen, your favorite sniffer, ethereal, tcpdump, etc. There are also hardware boxes that do intelligent L7 classification, and I would assume some of the commercial sniffers do that too. Obviously they cannot see the session's plaintext, but they can see enough to identify with assurance that the protocol in use is SSH - that much is NOT hidden. Telnet to an ssh server on its port and see for yourself - the greeting banner is something like this:

SSH-2.0-OpenSSH_3.7.1p2

Even without digging in much, if a sysadmin with a clue is wondering what you're running, he can telnet to the server's port by hand, get this banner, and know what's up. Similarly, it'll be in the first data payload back from the server on a new TCP connection, conveniently at the beginning of what your sniffer would have recorded for the session.
 

buleyb

Golden Member
Aug 12, 2002
1,301
0
0
Originally posted by: eigen
Exactly how would the admin inspect the payload on a ssh connection?

pretty much said already, but you don't need to inspect the data being encrypted to get an idea whats going on.

and Carl, if you are bored enough to toss work ethic aside, tell your manager or bring a book, all this is regardless to the fact that you know you aren't supposed to be doing it, but you still do. People like you are the reason corporate usage policies became so necessary.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |