2014-10-17 20:49 GMT+02:00 Bret Lambert <bret.lamb...@gmail.com>: > Well, if, as Herr Schroeder seems to be implying, this is used to > avoid port scans, I'd look for traffic to/from address:port which > don't show up on scans.
That's certainly possible but more expensive than "find all ssh servers". Best Martin