On the other, people using this tool are more likely to take steps to secure their servers.
SSH Check – public SSH server testing tool
51–60 of 125 posts
Re: SSH Check – public SSH server testing tool
#52Anyway.. just to reiterate I'm not trying accuse you of anything OP. Very cool utility, nice work!
Re: SSH Check – public SSH server testing tool
#53Re: SSH Check – public SSH server testing tool
#54Is it just me or am I the only one who is a bit hesitant to submit the public IP/hostname to some random service on the web. I'm not trying to say that the creator of this has any ill intent, but I also don't know that they aren't cataloging addresses of potentially vulnerable ssh daemons. Anyway.. just to reiterate I'm not trying accuse you of anything OP. Very cool utility, nice work!
Or to put it another way: if you're worried that your SSH is vulnerable, fix it. Don't rely on not typing it into a website, because people will find it regardless.
Re: SSH Check – public SSH server testing tool
#55Re: SSH Check – public SSH server testing tool
#56Is it just me or am I the only one who is a bit hesitant to submit the public IP/hostname to some random service on the web. I'm not trying to say that the creator of this has any ill intent, but I also don't know that they aren't cataloging addresses of potentially vulnerable ssh daemons. Anyway.. just to reiterate I'm not trying accuse you of anything OP. Very cool utility, nice work!
Re: SSH Check – public SSH server testing tool
#57An error occurred This happenned when we were trying to connect to io.r1ch.net:22.
Re: SSH Check – public SSH server testing tool
#58Is it just me or am I the only one who is a bit hesitant to submit the public IP/hostname to some random service on the web. I'm not trying to say that the creator of this has any ill intent, but I also don't know that they aren't cataloging addresses of potentially vulnerable ssh daemons. Anyway.. just to reiterate I'm not trying accuse you of anything OP. Very cool utility, nice work!
If they wanted to find vulnerable ssh daemons it would be much faster and easier to scan the web than wait for people to enter their details here. Or to put it another way: if you're worried that your SSH is vulnerable, fix it. Don't rely on not typing it into a website, because people will find it regardless.
In my experience, if you have an SSH port accessible from the internet, it has been probed today by a few Chinese/Russian IPs. Unless my raspberry pi home server is somehow a high value intelligence target...
Re: SSH Check – public SSH server testing tool
#59Is it just me or am I the only one who is a bit hesitant to submit the public IP/hostname to some random service on the web. I'm not trying to say that the creator of this has any ill intent, but I also don't know that they aren't cataloging addresses of potentially vulnerable ssh daemons. Anyway.. just to reiterate I'm not trying accuse you of anything OP. Very cool utility, nice work!
However, here's my perspective:
- if the server is public already then black hats can simply probe your networks (IPv4 is not that big) and find the servers by themselves. The odds are that hackers are probably not interested in your company anyway.
- there are people who don't care about security of their servers (or rather are lazy / naive) and might find this service useful. Even if we were black hats it would at last alarm them that something is wrong. If they ignore the warnings - well - god help them.
EDIT: typos
Re: SSH Check – public SSH server testing tool
#60Earlier quoted context omitted.
Thank you! (my site)... SSLPing didn't get as much attention on HN as SSHCheck does...
Well then let me thank you again :) Very slick UI, signed up in seconds, set myself up in under a minute. What are your plans with it? Just leaving a free service running or do you want to add paid plans as well? (and if not, I would recommend setting up at least a "Support" plan of some kind; it sends a strong signal)
I have no set plan yet (the site is 1yr old)... SSLPing monitors almost 6000 servers daily, 250+ users... so maybe I'll follow your advice with some kind of support plan (I was thinking of donations)