this post was submitted on 25 Dec 2024
14 points (100.0% liked)
Hacker News
2334 readers
385 users here now
Posts from the RSS Feed of HackerNews.
The feed sometimes contains ads and posts that have been removed by the mod team at HN.
founded 11 months ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
If you are willing to install this, why not configure the system to block an IP if it starts connecting to multiple closed ports? Something like crowdsec or fail2ban can do this. Then the attacker gets far less info - looks like all ports are closed and can be done for more then 8 hours.