Re: ssh "banner"

2002-10-22 Thread Javier Fernández-Sanguino Peña
On Fri, Oct 18, 2002 at 11:08:52AM -0400, Phillip Hofmeister wrote: > On Fri, 18 Oct 2002 at 03:50:12PM +0200, [EMAIL PROTECTED] wrote: > > Why isn't it done by default ? > You would have to ask the maintainer... > Oh! Better: file a bug. No! Wait! It's already done [1] >:-|

Re: ssh "banner"

2002-10-22 Thread Javier Fernández-Sanguino Peña
I'm starting to get bored of pople replying nonsense without tesint it themselves. On Fri, Oct 18, 2002 at 09:19:01PM +0200, Vasarhelyi asd Daniel wrote: > > issue(5) might help some of you about pre-login banner and daemon(s) > > banner version. > Banner gets diplayed _after_ successful l

Re: ssh "banner"

2002-10-22 Thread Javier Fernández-Sanguino Peña
On Fri, Oct 18, 2002 at 11:08:52AM -0400, Phillip Hofmeister wrote: > On Fri, 18 Oct 2002 at 03:50:12PM +0200, [EMAIL PROTECTED] wrote: > > Why isn't it done by default ? > You would have to ask the maintainer... > Oh! Better: file a bug. No! Wait! It's already done [1] >:-|

Re: ssh "banner"

2002-10-22 Thread Javier Fernández-Sanguino Peña
I'm starting to get bored of pople replying nonsense without tesint it themselves. On Fri, Oct 18, 2002 at 09:19:01PM +0200, Vasarhelyi asd Daniel wrote: > > issue(5) might help some of you about pre-login banner and daemon(s) > > banner version. > Banner gets diplayed _after_ successful l

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > killall -9 sshd > > done Isn't that a bit extreme? /etc/init.d/sshd restart would do just fine without any of that forcing. -- Regards, Time 13 \ 9 . 3 clockbot.net / 6 msg07477/pgp0.pgp Desc

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:51:49PM +0200, vdongen wrote: > afaik /etc/issue.net is intended for telnet and not for ssh. Are you saying using /etc/issue.net is a security risk or that it will not work? I use /etc/issue.net on all my sshd's without problems(fwiw) -- Regards, Time 13

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > killall -9 sshd > > done Isn't that a bit extreme? /etc/init.d/sshd restart would do just fine without any of that forcing. -- Regards, Time 13 \ 9 . 3 clockbot.net / 6 pgpOB7u3DBaoN.pgp Descripti

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:51:49PM +0200, vdongen wrote: > afaik /etc/issue.net is intended for telnet and not for ssh. Are you saying using /etc/issue.net is a security risk or that it will not work? I use /etc/issue.net on all my sshd's without problems(fwiw) -- Regards, Time 13

Re: ssh "banner"

2002-10-21 Thread przemolicc
On Fri, Oct 18, 2002 at 04:13:22PM +0200, Johannes Berth wrote: > * [EMAIL PROTECTED] <[EMAIL PROTECTED]>: > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > > > How can I disable the message ? > > You don't want to disable it. Oh, really ?! Are you refering to "SSH-2.0" or to "OpenSSH_3.4p1 Debian

Re: ssh "banner"

2002-10-18 Thread Vasarhelyi asd Daniel
> issue(5) might help some of you about pre-login banner and daemon(s) > banner version. Banner gets diplayed _after_ successful login, but ssh "handshake" needs some information about server ssh version. There was a big flame about the "3.4p1 Debian 1:3.4p1-1" part of message. It can _not_ be "ma

Re: ssh "banner"

2002-10-18 Thread Vasarhelyi asd Daniel
> issue(5) might help some of you about pre-login banner and daemon(s) > banner version. Banner gets diplayed _after_ successful login, but ssh "handshake" needs some information about server ssh version. There was a big flame about the "3.4p1 Debian 1:3.4p1-1" part of message. It can _not_ be "ma

Re: ssh "banner"

2002-10-18 Thread Phillip Hofmeister
On Fri, 18 Oct 2002 at 03:50:12PM +0200, [EMAIL PROTECTED] wrote: > Why isn't it done by default ? You would have to ask the maintainer... -- Phil PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import XP Source Code: #include #include

Re: ssh "banner"

2002-10-18 Thread Mike Renfro
On Fri, Oct 18, 2002 at 03:50:12PM +0200, [EMAIL PROTECTED] wrote: > > You can; however, recompile and get rid of the "Debian 1:3.4p1-1" part... > > Why isn't it done by default ? 9-12 months down the road (or whenever the next exploit in OpenSSH is found), Debian will likely backport the fix in

Re: ssh "banner"

2002-10-18 Thread Xavier Santolaria
issue(5) might help some of you about pre-login banner and daemon(s) banner version. -xavier On Fri, Oct 18, 2002 at 03:30:01PM +0200, Tobias Rosenstock wrote: > edit /etc/ssh/sshd_config and put a comment mark (#) at the beginning of > the line that says > Banner /etc/issue.net > or something li

Re: ssh "banner"

2002-10-18 Thread Attila Nagy
Hello, > > You can; however, recompile and get rid of the "Debian 1:3.4p1-1" part... > Why isn't it done by default ? FreeBSD started this to get rid of users, complaining about the old OpenSSH in the base system and to indicate that their OpenSSH is not the 2.3.0, but a security patched one. Fre

Re: ssh "banner"

2002-10-18 Thread Johannes Berth
* [EMAIL PROTECTED] <[EMAIL PROTECTED]>: > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? You don't want to disable it.

Re: ssh "banner"

2002-10-18 Thread Johannes Berth
* Aleksander Iwanski <[EMAIL PROTECTED]>: > Edit sshd_config > find the line with something like > Banner /etc/issue.net That's not the banner he's talking about. > killall -9 sshd There are better ways to stop the ssh daemon.

Re: ssh "banner"

2002-10-18 Thread vdongen
> > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > Edit sshd_config > > find the line with something like > > Banner /etc/issue.net > > and set > > # Banner /etc/issue.net > > killall -9 sshd > > done > > > Regards afaik /etc/issue.net is intended for telnet and not for ssh. furthermore: $ n

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 09:42:14AM -0400, Phillip Hofmeister wrote: > On Fri, 18 Oct 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debia

Re: ssh "banner"

2002-10-18 Thread Xavier Santolaria
This won't do the trick, AFAIK it will only display /etc/issue.net content before the password prompt, but wont change/hide the version of the sshd when telnet'ing localhost || ip on port 22. -xavier > Edit sshd_config > > find the line with something like > > Banner /etc/issue.net > > and se

Re: ssh "banner"

2002-10-18 Thread Tobias Rosenstock
Hi, On Fri, 18 Oct 2002, vdongen wrote: > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > > > How can I disable the message ? > This banner is needed info

Re: ssh "banner"

2002-10-18 Thread Xavier Santolaria
You can still have a look there: http://groups.google.com/groups?selm=cy9se16re.fsf%40zeus.theos.com&output=gplain for an answer, but would be better to not touch it. If you can restrict the access to port 22 for a few ip's, do it and block the rest. Will save you some sleepless nights if you'r

Re: ssh "banner"

2002-10-18 Thread Phillip Hofmeister
On Fri, 18 Oct 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > Edit sshd_config > > find the line with something like > > Banner /etc/issue.net That will not get rid of the version identification string. -- Phil PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > On Fri, Oct 18, 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-Ope

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 03:30:01PM +0200, Tobias Rosenstock wrote: > On Fri, 18 Oct 2002 [EMAIL PROTECTED] wrote: > > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3

Re: ssh "banner"

2002-10-18 Thread Phillip Hofmeister
On Fri, 18 Oct 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? If you attempt to "disable" thi

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 03:23:18PM +0200, vdongen wrote: > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > > > How can I disable the message ? > This bann

Re: ssh "banner"

2002-10-18 Thread Vincent Hanquez
On Fri, Oct 18, 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? you can't without

Re: ssh "banner"

2002-10-18 Thread Tobias Rosenstock
On Fri, 18 Oct 2002 [EMAIL PROTECTED] wrote: > Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? edit /etc/ssh/sshd_config and put a comme

Re: ssh "banner"

2002-10-18 Thread Mark Janssen
On Fri, 2002-10-18 at 14:58, [EMAIL PROTECTED] wrote: > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? You can limit it somewhat (by editing source), but the protocol needs the version string, so you can't change it without breaking compatibility. -- Mark Janssen --

Re: ssh "banner"

2002-10-18 Thread vdongen
> Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? This banner is needed information for a ssh client connecting to your server, therefo

Re: ssh "banner"

2002-10-18 Thread Aleksander Iwanski
On Fri, Oct 18, 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 Edit sshd_config find the line with something like B

Re: ssh "banner"

2002-10-18 Thread Phillip Hofmeister
On Fri, 18 Oct 2002 at 03:50:12PM +0200, [EMAIL PROTECTED] wrote: > Why isn't it done by default ? You would have to ask the maintainer... -- Phil PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import XP Source Code: #include #include

ssh "banner"

2002-10-18 Thread przemolicc
Woody host:/home/przemol>telnet 192.168.x.y ssh Trying 192.168.x.y... Connected to 192.168.x.y. Escape character is '^]'. SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 How can I disable the message ? przemol

Re: ssh "banner"

2002-10-18 Thread Mike Renfro
On Fri, Oct 18, 2002 at 03:50:12PM +0200, [EMAIL PROTECTED] wrote: > > You can; however, recompile and get rid of the "Debian 1:3.4p1-1" part... > > Why isn't it done by default ? 9-12 months down the road (or whenever the next exploit in OpenSSH is found), Debian will likely backport the fix in

Re: ssh "banner"

2002-10-18 Thread Xavier Santolaria
issue(5) might help some of you about pre-login banner and daemon(s) banner version. -xavier On Fri, Oct 18, 2002 at 03:30:01PM +0200, Tobias Rosenstock wrote: > edit /etc/ssh/sshd_config and put a comment mark (#) at the beginning of > the line that says > Banner /etc/issue.net > or something li

Re: ssh "banner"

2002-10-18 Thread Johannes Berth
* [EMAIL PROTECTED] <[EMAIL PROTECTED]>: > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? You don't want to disable it. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: ssh "banner"

2002-10-18 Thread Attila Nagy
Hello, > > You can; however, recompile and get rid of the "Debian 1:3.4p1-1" part... > Why isn't it done by default ? FreeBSD started this to get rid of users, complaining about the old OpenSSH in the base system and to indicate that their OpenSSH is not the 2.3.0, but a security patched one. Fre

Re: ssh "banner"

2002-10-18 Thread Johannes Berth
* Aleksander Iwanski <[EMAIL PROTECTED]>: > Edit sshd_config > find the line with something like > Banner /etc/issue.net That's not the banner he's talking about. > killall -9 sshd There are better ways to stop the ssh daemon. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 09:42:14AM -0400, Phillip Hofmeister wrote: > On Fri, 18 Oct 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debia

Re: ssh "banner"

2002-10-18 Thread vdongen
> > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > Edit sshd_config > > find the line with something like > > Banner /etc/issue.net > > and set > > # Banner /etc/issue.net > > killall -9 sshd > > done > > > Regards afaik /etc/issue.net is intended for telnet and not for ssh. furthermore: $ n

Re: ssh "banner"

2002-10-18 Thread Xavier Santolaria
You can still have a look there: http://groups.google.com/groups?selm=cy9se16re.fsf%40zeus.theos.com&output=gplain for an answer, but would be better to not touch it. If you can restrict the access to port 22 for a few ip's, do it and block the rest. Will save you some sleepless nights if you'r

Re: ssh "banner"

2002-10-18 Thread Phillip Hofmeister
On Fri, 18 Oct 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > Edit sshd_config > > find the line with something like > > Banner /etc/issue.net That will not get rid of the version identification string. -- Phil PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 03:30:01PM +0200, Tobias Rosenstock wrote: > On Fri, 18 Oct 2002 [EMAIL PROTECTED] wrote: > > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3

Re: ssh "banner"

2002-10-18 Thread Phillip Hofmeister
On Fri, 18 Oct 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? If you attempt to "disable" thi

Re: ssh "banner"

2002-10-18 Thread Tobias Rosenstock
Hi, On Fri, 18 Oct 2002, vdongen wrote: > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > > > How can I disable the message ? > This banner is needed info

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 03:23:18PM +0200, vdongen wrote: > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > > > How can I disable the message ? > This bann

Re: ssh "banner"

2002-10-18 Thread Xavier Santolaria
This won't do the trick, AFAIK it will only display /etc/issue.net content before the password prompt, but wont change/hide the version of the sshd when telnet'ing localhost || ip on port 22. -xavier > Edit sshd_config > > find the line with something like > > Banner /etc/issue.net > > and se

Re: ssh "banner"

2002-10-18 Thread przemolicc
On Fri, Oct 18, 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > On Fri, Oct 18, 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > > Woody > > > > host:/home/przemol>telnet 192.168.x.y ssh > > Trying 192.168.x.y... > > Connected to 192.168.x.y. > > Escape character is '^]'. > > SSH-2.0-Ope

Re: ssh "banner"

2002-10-18 Thread Vincent Hanquez
On Fri, Oct 18, 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? you can't without

Re: ssh "banner"

2002-10-18 Thread Tobias Rosenstock
On Fri, 18 Oct 2002 [EMAIL PROTECTED] wrote: > Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? edit /etc/ssh/sshd_config and put a comme

Re: ssh "banner"

2002-10-18 Thread Mark Janssen
On Fri, 2002-10-18 at 14:58, [EMAIL PROTECTED] wrote: > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? You can limit it somewhat (by editing source), but the protocol needs the version string, so you can't change it without breaking compatibility. -- Mark Janssen --

Re: ssh "banner"

2002-10-18 Thread vdongen
> Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > How can I disable the message ? This banner is needed information for a ssh client connecting to your server, therefo

Re: ssh "banner"

2002-10-18 Thread Aleksander Iwanski
On Fri, Oct 18, 2002 at 02:58:44PM +0200, [EMAIL PROTECTED] wrote: > Woody > > host:/home/przemol>telnet 192.168.x.y ssh > Trying 192.168.x.y... > Connected to 192.168.x.y. > Escape character is '^]'. > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 Edit sshd_config find the line with something like B

ssh "banner"

2002-10-18 Thread przemolicc
Woody host:/home/przemol>telnet 192.168.x.y ssh Trying 192.168.x.y... Connected to 192.168.x.y. Escape character is '^]'. SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 How can I disable the message ? przemol -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Cont