So you're operating with a compromised user account capable of killing your sshd on port 1234 but there's no other local escalation exploits?
Seems like something a little script or patch could fix up really easily - make sure your daemon is running on port 1234. If it's not, take whatever defensive measures you think would be effective.