Allowing remote root login

Tom Buskey tom at buskey.name
Thu Oct 16 12:14:07 EDT 2003


bscott at ntisys.com wrote:
> On Thu, 16 Oct 2003, at 3:57pm, invalid at pizzashack.org wrote:
> 

Stuff deleted....
> 
>   I notice that you've set your headers to list From as
> <invalid at pizzashack.org>, obviously an invalid address.  That makes a huge
> amount of sense to me.  Now you're not broadcasting your email address.  
> Much better!  In fact, when I first saw it, I thought, "Wow.  What a good
> idea.  Why didn't I think of that?"
> 

I have a free email address that redirects to my real address: 
spamme at punkass.com.  It's a valid email address but I get little spam on 
it.  Probably because the harvesting software discards addresses with 
"spam" in them.  Thanks to everyone who puts SPAM in the middle of thier 
email postings :-)

In a similar vein, I don't run sshd on port 22.  I don't get any extra 
security by that but all the ssh scanners and script kiddies scan port 
22 by default.  So instead of *everyone* rattling the door handle, I 
only get valid users and more clever, determined scanners.  Maybe I 
can't keep them out, but their scans are not lost in the noise of the 
script kiddies.

I see 'invalid@*' as likely to get disregarded by some spammers, etc.  I 
think spam@ would be dismissed even more.  Sometimes a little 
misdirection is good even though it's not security by any means.




More information about the gnhlug-discuss mailing list