Assume compromise: I typo'd 2222 as 22222 in sshd_config, restarted, closed terminal. Blast radius: one fresh ubuntu vm on a provider I shall not name. Attack surface: port 22222, listening, no client configured for it. Zero trust in my own fingers. Took six hours to recover via vnc because the control panel lagged and I refused to pay for phone support. threat model your typos, folks. zero trust means zero trust, even in yourself.
Funny: I typo'd my SSH port and locked myself out for 6 hours
Oh man this reminds me of the time I typo'd my own name in a sudoers file (don't ask why I was putting my name in sudoers it was a very long night and I was trying to set up some automated deployment thing for a friend's project that never actually launched because he got distracted by a new framework) and the worst part was I didn't realize until I tried to fix something else and suddenly I was locked out of sudo entirely and had to boot into single user mode which on this particular machine took forever because it was one of those old bios systems that checks every single ram stick individually and speaks to you in beep codes (remember beep codes) and by the time I got back in I'd forgotten what I was originally trying to fix so I just reinstalled the whole os and started over which in hindsight was probably faster anyway but still the feeling of your own fingers betraying you is somet
This is why I keep ipmi sol enabled on anything I colo. Specs for my remote rescue kit:
- Supermicro x10 with dedicated bmc nic
- 16gb usb rescue stick, ventoy loaded
- Serial cable, rj45 to db9 adapter
- Spare sata ssd with known-good os image
Six hours of downtime on a vm? My raid6 rebuild takes longer, but at least I planned for it.
This is why you test sshd config with sshd -t before restart. For what it's worth, the real risk isn't the lockout, it's that port 22222 is in the ephemeral range and some automated scanners will hit it eventually. Your spf record for that vnc session was probably more reliable than your ssh config. Also, dmarc none on the provider's status page emails, I checked. Not a good sign.
Had to call the isp and pretend I didn't know why it was down. Took eight hours because the tech read me the config over the phone, line by line, and I had to act surprised at each error. Warm memory now. Kids with their api consoles will never know the romance of a 9600 baud console cable and a prayer.