LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-19-2005, 02:13 PM   #1
Steve Cronje
Member
 
Registered: Jan 2003
Location: Canada
Distribution: Ubuntu, Mepis, Debian
Posts: 158

Rep: Reputation: 31
Is there any benefit to spoofing SSH version string, and how do I do that?


I am trying to harden a webserver that has OpenSSH running.

Is there any benefit to spoofing the version string that is reported when running, say, nmap against the host?

If so, how do I do that? I am running Debian stable, so I would prefer to use apt-get to keep updated without needing to configure/make/make install with every security update.

I haven't had much luck with the man-pages or Google.

Thanks for any suggestions.
Steve

Last edited by Steve Cronje; 01-19-2005 at 02:24 PM.
 
Old 01-19-2005, 03:08 PM   #2
Hangdog42
LQ Veteran
 
Registered: Feb 2003
Location: Maryland
Distribution: Slackware
Posts: 7,803
Blog Entries: 1

Rep: Reputation: 422Reputation: 422Reputation: 422Reputation: 422Reputation: 422
I'd have to say that crackers pay absolutely no attention to the information being returned to them. It looks to me like they always just take a rip at the IP address just to see if it breaks. If it does, then they pay attention, but if it doesn't, its on to the next IP address. The reason I say that is that I haven't hidden the fact that I have an Apache server running on Linux, yet my logs are filled with attempts to crack into IIS. I also keep a openSSH very well patched, yet every day at least one person has a go at it, even though they should be able to see I'm running an SSH version that doesn't have any known exploits.

Personally, I think your time and effort would be better spent on other security aspects. Sending bad information back just doesn't strike me as having any deterrent value.
 
Old 01-19-2005, 05:17 PM   #3
Steve Cronje
Member
 
Registered: Jan 2003
Location: Canada
Distribution: Ubuntu, Mepis, Debian
Posts: 158

Original Poster
Rep: Reputation: 31
Quote:
Originally posted by Hangdog42
I'd have to say that crackers pay absolutely no attention to the information being returned to them.
Yes, I have seen that too.

Quote:

Personally, I think your time and effort would be better spent on other security aspects. Sending bad information back just doesn't strike me as having any deterrent value.
That is true, I was just wondering if there was an easy way to add another layer. The less information given out the better. I must say, I might have phrased my initial question poorly. What I was hoping to do, was simply return, say, "SSH" in the string, rather than all the version details. If that was an easy fix, it might add a little more security.

Thanks for the comments.
Steve
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Email clients, what's the benefit? unityxx311 Linux - Software 3 10-27-2005 11:19 AM
Parse RPM version string in Bash jimwelc Linux - Newbie 1 02-28-2005 05:22 PM
setting version string linuxdev Linux - Newbie 1 02-13-2004 09:35 AM
Geek Gear to benefit the FSF and EFF KingofBLASH General 3 02-04-2004 06:56 PM
whats this? ssh version # sopiaz57 Linux - General 4 06-08-2003 12:23 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:04 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration