Re: Openssh and sendmail signatures

From: Kurt Seifried (bugtraq@seifried.org)
Date: 09/11/02


From: "Kurt Seifried" <bugtraq@seifried.org>
To: <monz@danbbs.dk>, "focus-linux" <focus-linux@securityfocus.com>
Date: Wed, 11 Sep 2002 12:48:14 -0600


> How do I prevent Openssh telling which version is running?
> Likewise with sendmail? (I know you'll tell med to use another MTA..).
>
> Surely it's a problem with my eyes, haven't found out yet, though.

Part of the OpenSSH spec requires you to tell the remote end what version
you are running, i.e. so it knows what the capabilities are. You could
pretend to run a different version but may run into trouble. As for sendmail
I can still figure out what version you have based on error codes/etc.
Fiddling with banners is cute but largely useless since few mass attackers
bother to scan anymore, they simply shotgun out the attacks and see what
comes back. You will still be running an insecure version of whatever
software if you do not regularily patch it/etc.

Kurt Seifried, kurt@seifried.org
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://seifried.org/security/



Relevant Pages

  • make release questions...
    ... I have been mucking about w/ 'make release' for some time now (stripping ... out OpenSSH, sendmail, Heimdal, bits oF BIND, etc.) and while I now have ...
    (freebsd-stable)
  • Re: SunSSH vulnerable
    ... sun's ssh is openssh and as my understanding is that sun no longer maintains its ... own version of sendmail any more; instead it uses freeware versions after ... >> that Sun get themselves into. ... >> in security bugs and taken appropriate precautions. ...
    (comp.unix.solaris)
  • Re: SunSSH vulnerable
    ... sun's ssh is openssh and as my understanding is that sun no longer maintains its ... own version of sendmail any more; instead it uses freeware versions after ... >> that Sun get themselves into. ... >> in security bugs and taken appropriate precautions. ...
    (comp.sys.sun.admin)
  • [Full-disclosure] Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Ju
    ... You would probably expect me to the be last person to say that Sendmail ... But what did you pay for Sendmail? ... the same holds true with OpenSSH. ... is ever a security problem in OpenSSH we will disclose it ...
    (Full-Disclosure)