Re: Prevent banner grabbing
From: Jeff P. Van Dyke (jpv_at_vandyke.com)
To: "Byron Sonne" <email@example.com>, "Andrea Riela" <firstname.lastname@example.org> Date: Wed, 10 Dec 2003 16:00:24 -0700
> > I've a system with openBSD 3.3 and OpenSSH_3.7.1.
> > How could I prevent a banner grabbing?
> You can't.
> As far as I know, the protocol spec *requires* the banner to be sent
> so that connecting clients can determine what protocol versions to
The protocol requires the first part of the banner to be sent.
I don't recall if OpenSSH lets you change this, but other
implementations including ours allow you to configure the
banner to be more generic. For example, changing it from:
Jeff P. Van Dyke