2014-10-17 20:49 GMT+02:00 Bret Lambert <[email protected]>: > Well, if, as Herr Schroeder seems to be implying, this is used to > avoid port scans, I'd look for traffic to/from address:port which > don't show up on scans.
That's certainly possible but more expensive than "find all ssh servers". Best Martin

