Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    31

    Default Removing SSH type/version broadcast

    Many vulnerablity scans and "secure/harden your server" tutorials recommend removing the type and version messages from the login/connect of common services to make it more difficult for hackers to know the contents of the server. Other posts have info on how to remove this for Apache, Exim and Bind, but I have not found anyplace to remove it for OpenSSH. Does anyone know how to prevent OpenSSH from indicating:
    SSH-1.99-OpenSSH_3.6.1p2
    and replacing with something like:
    SSH

  2. #2
    Super Moderator This forum account has been confirmed by cPanel staff to represent a vendor. chirpy's Avatar
    Join Date
    Jun 2002
    Location
    Go on, have a guess
    Posts
    13,495

    Default

    I'm not aware of a way. You'll probably have to go and have a trawl through the openssh documentation on their site.
    Jonathan Michaelson

    Need your cPanel servers secured and tuned?
    cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services
    Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf
    http://www.configserver.com

  3. #3
    cPanel Partner NOC cPanel Partner NOC Badge shashank's Avatar
    Join Date
    Apr 2003
    Posts
    146

    Default

    something similar is discussed at :

    http://lists.debian.org/debian-secur.../msg00062.html

    You might want to have a look.
    Shashank Wagh.
    Systems Administrator.
    http://www.shashank.net

  4. #4
    Member
    Join Date
    Mar 2004
    Posts
    31

    Default

    Thanks for the info.

    The debian thread was interesting and I might have agreed with it back in 2002 when it looks like a lot of it was posted. Unfortunately, many of our clients are now being forced into using vulnerablity scanning services by the credit card industry and the last 4 services I have seen report the boradcast of OpenSSH type and version as a lower level vulnerablity that should be removed.

    Since it does not appear that OpenSSH shares this view, we'll stop looking for a way to remove it for now.

    Thanks again!

  5. #5
    cPanel Partner NOC cPanel Partner NOC Badge shashank's Avatar
    Join Date
    Apr 2003
    Posts
    146

    Default

    You are welcome :-)
    Shashank Wagh.
    Systems Administrator.
    http://www.shashank.net

Similar Threads & Tags
Similar threads

  1. Pls help with account type and system type domain zone config
    By stardotstar in forum E-mail Discussions
    Replies: 2
    Last Post: 09-21-2009, 03:27 PM
  2. Removing Server version info from default pages
    By zerokarma in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 10-06-2008, 10:21 PM
  3. Ssh and kernel version
    By black&white in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 09-25-2006, 09:22 AM
  4. Cannot get latest version of SSH to install
    By trackpads in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 07-06-2004, 10:31 PM
  5. Does CPanel SSH Applet use version 1 only?
    By gator in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 06-02-2004, 10:57 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube