@haruna_adoga: 89% of Linux attacks target SSH. Spin up a fresh server and check the auth log 90 seconds later. Hundreds of failed login attempts before the deployment script has even finished. Here are the 8 directives that lock SSH down properly. Every sysadmin needs this saved. Part 2 drops Sunday 🐧 Free Linux and RHCSA course on YouTube - link in bio 🐧 ssh hardening linux | harden ssh linux | sshd_config hardening | linux ssh security | openssh hardening | ssh brute force protection | linux server security | permitrootlogin no | passwordauthentication no | ssh ed25519 | allowusers sshd | linux hardening checklist | rhcsa ssh | linux cybersecurity | sshd config explained #linux #ssh #cybersecurity #sysadmin #devops

Haruna Adoga
Haruna Adoga
Open In TikTok:
Region: GB
Saturday 22 August 2026 08:32:08 GMT
37725
1549
44
196

Music

Download

Comments

iveky3
Ivica Buljević :
why even expose ssh to internet!?
2026-08-24 08:36:52
1
wesanderson00
Fresh cut potato's :
I dont use ssh. nothing to harden if it doesn't exist
2026-08-24 00:36:54
3
alex.morgan480
Alex Morgan :
Maybe just stop opening of SSH for entire world? It's should be available only from LAN, and if you need, you can connect to that LAN from remote, using VPN.
2026-08-22 14:55:48
5
totof77181
christophel77 :
Change the SSH port. Add Fail2ban to SSH with a configuration that allows three login attempts and permanently bans the IP address. And to add an extra layer of security, use iptables or nftables to allow specific IP addresses to connect
2026-08-22 15:34:15
3
user4545619372411
user4545619372411 :
loglevel verbose destroys your SSDs with useless log writes.
2026-08-22 09:29:28
3
lnnsntg379
lnnsntg379 :
But the most important part of that configuration is missing: AuthenticationMethods publickey This rule requires authentication only by key pairs. Also check for include files that overwrite the configuration. These are usually other files that are loaded in the background in addition to the initial configuration file. Include /etc/ssh/sshd_config.d/*.conf
2026-08-22 13:39:47
2
feras_alzarouq
feras alzarouq :
Changing the default SSH port is also useful.
2026-08-22 14:58:39
2
kaake98
kaake :
nobody talking about `knockd`
2026-08-22 23:39:18
1
toxovi9948
toxovi9948 :
I added my VPS to my tailscale network and allowed ssh only from the tailscale0 network in UFW 😉
2026-08-22 14:29:31
3
tetrawhopper
Tetrawhopper :
89% fanatasy number. Most attacks are on web interfaces, phishing and Active Directory.
2026-08-23 08:47:25
1
krzysztofas8
Krzysztof :
iptables ratelimit and sshguard
2026-08-22 09:22:31
1
zup0042
PhoenixRider💚 :
we deploy a temporary firewall rule that only allows access to ssh ports from the one operator IP address while the system isn't even online yet. Faster, safer and easier overall
2026-08-22 12:09:46
1
i6tim
i6tim :
Install crowdsec trust me. way more secure than fail2ban itself
2026-08-22 23:34:23
1
.carcicc
Carlo :
Or just use a strong password?
2026-08-23 09:37:17
1
viktor4n6
Viktor :
Useful to study to CompTIA Security+ thanks you
2026-08-23 06:28:30
1
frankneumeisterfr
Frank Neumeister (Fritz) :
I don't run sshd......
2026-08-22 14:13:13
1
_jodi33
_jodi33 :
i have my ssh port changed to a diffrent port outside the 3000 range that most scanners go for
2026-08-22 13:37:59
1
user31218468731746
xavz :
Beginner with Linux, but the wealth of knowledge here, wow!!!
2026-08-22 18:18:57
1
to.vik
Tío Vik :
...you're missing the cherry on top: fail2ban. three bad attempt and you're out, ip banned for 15 days or more...😉😉😉
2026-08-22 13:26:25
1
user6990412909009
user6990412909009 :
fail2ban
2026-08-22 11:24:59
2
willam00234
User828648376373829 :
👍👍👍
2026-08-23 06:54:19
1
To see more videos from user @haruna_adoga, please go to the Tikwm homepage.

Other Videos


About