LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Other *NIX Forums > *BSD
User Name
Password
*BSD This forum is for the discussion of all BSD variants.
FreeBSD, OpenBSD, NetBSD, etc.

Notices


Reply
  Search this Thread
Old 07-11-2007, 05:42 AM   #1
JF1980
LQ Newbie
 
Registered: Mar 2003
Posts: 26

Rep: Reputation: 15
Disable SSHv1 (OpenBSD)


Hello chaps, I've been trying to disable SSHv1 on my OpenBSD firewall. I edited the /etc/ssh/sshd.config file to show:

Port 22
Protocol 2

So what happens? It's all very strange. I now keep seeing:

Jul 11 10:20:44 hal-5 sshd[22430]: fatal: buffer_get: trying to get more bytes 129 than in buffer 34
Jul 11 10:23:10 hal-5 sshd[2928]: fatal: buffer_get: trying to get more bytes 129 than in buffer 34

In /var/log/authlog.

If I try to connect with SSHv1 that host is instantly added to hosts.deny and any further attempts to connect (even with SSHv2) are blocked with the authlog showing: sshd [] Did not receive identification string from x.x.x.x which I'm guessing is due to hosts.deny blocking the connection. Is this 'normal' behavior or is it being caused by my OSSEC HIDS?

I'm tasked with disabling SSHv1 on all external IP's but I don't want to end up locking myself out of a remote gateway! Is the above all normal and have I disabled SSHv1 correctly?

Many Thanks.
 
Old 07-11-2007, 11:37 PM   #2
leosgb
Member
 
Registered: Nov 2004
Location: Brazil
Distribution: Gentoo
Posts: 363

Rep: Reputation: 31
To disable it you just need to stop the service. And then remove it from your initialization script. For Gentoo I would:

/etc/init.d/sshd stop
rc-update del sshd default

Hope this helps.
 
Old 07-12-2007, 03:43 AM   #3
JF1980
LQ Newbie
 
Registered: Mar 2003
Posts: 26

Original Poster
Rep: Reputation: 15
Thanks but actually I had already disabled it as noted above. I only wanted to disable Protocol version 1 not SSH altogether.
 
Old 07-12-2007, 10:06 AM   #4
leosgb
Member
 
Registered: Nov 2004
Location: Brazil
Distribution: Gentoo
Posts: 363

Rep: Reputation: 31
Sorry, misunderstood your question
 
Old 07-12-2007, 12:48 PM   #5
JF1980
LQ Newbie
 
Registered: Mar 2003
Posts: 26

Original Poster
Rep: Reputation: 15
No problem, thanks for the reply

FYI I found out that it's the OSSEC HIDS that blocks clients who have tried to connect with SSHv1. A nice feature actually, it was just a little worrying the first time I checked to see if v1 was disabled properly!

Code:
# ssh mybox.com -1
Protocol miss match 1 against 2.
# ssh mybox.com -2


...nothing; whoops!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
dbx command for corrosponding commands disable or disable on gdb bshankha AIX 0 09-26-2006 09:38 AM
Where to turn SSHv1 protocol and SSHv2 protocol on and off Minnie Nguyen Linux - Enterprise 3 07-05-2006 02:12 PM
OpenBSD - Where can i get OpenBSD 3.7 ISO CD -- Please help me b:z Linux - Software 5 04-08-2005 07:09 AM
OpenBSD - Where can i get OpenBSD 3.7 ISO CD -- Please help me b:z Linux - Software 1 04-07-2005 08:46 AM
what are the services i can disable, also disable ads, banners in konqueror? greythorne SUSE / openSUSE 3 03-16-2005 08:30 AM

LinuxQuestions.org > Forums > Other *NIX Forums > *BSD

All times are GMT -5. The time now is 02:13 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration