<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Version disclosure how to avoid it in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160381#M485002</link>
    <description>&lt;P&gt;Hi Torsten ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;grep "Banne" /opt/ssh/etc/sshd_config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Banner /home/test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cat /home/test&lt;/P&gt;&lt;P&gt;test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and again when am trying telnet 10.xx.xx.xx 22 &amp;nbsp;from my local machine to this server am able to get the ssh version .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 Aug 2013 12:53:52 GMT</pubDate>
    <dc:creator>chindi</dc:creator>
    <dc:date>2013-08-06T12:53:52Z</dc:date>
    <item>
      <title>Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160105#M484996</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Information disclosure in banner grab reveals sensitive data, such as technical details of the web server, environment, or user-specific data. This sensitive data may be used by an attacker to exploit the target web application, its hosting network, or its users. This helps an attacker to launch target specific attacks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to disable telnet ad ftp verisons , how do we do it ??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 08:18:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160105#M484996</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-06T08:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160185#M484997</link>
      <description>&lt;P&gt;Better to disable telnet and ftp anyway. Use ssh and scp or sftp instead.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 09:22:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160185#M484997</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2013-08-06T09:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160239#M484998</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We already have disabled telnet , but when we check from our local network say through telnet 10.xx.xx.xx &amp;nbsp;22 the ssh version must not be displayed .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;telnet&amp;nbsp;&lt;SPAN&gt;10.xx.xx.xx &amp;nbsp;22&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;OpenSSH 4.5p1sdtpfilecontrol-v1.1hpn12v14&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 10:35:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160239#M484998</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-06T10:35:00Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160309#M484999</link>
      <description>Look for a "banner" optin in "/etc/ssh/sshd_config".</description>
      <pubDate>Tue, 06 Aug 2013 11:56:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160309#M484999</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2013-08-06T11:56:45Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160357#M485000</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;Its nt working&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried&amp;nbsp;Banner /etc/issue&amp;nbsp;&lt;/P&gt;&lt;P&gt;/etc/issue contents as "TEST"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when i took a ssh session it showed up as ;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;login as: root&lt;BR /&gt;TEST&lt;BR /&gt;Using keyboard-interactive authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Its not my reqmnt.&lt;/P&gt;&lt;P&gt;My reqmnt is when am doing telnet to check port from a machine to that particular hpux 11iv2 server ,&lt;/P&gt;&lt;P&gt;telnet 10.xx.xx.xx 22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It must not display ssh version , only a blank screen must appear .&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 12:27:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160357#M485000</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-06T12:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160371#M485001</link>
      <description>Not /etc/issue but the ssh_config file!</description>
      <pubDate>Tue, 06 Aug 2013 12:37:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160371#M485001</guid>
      <dc:creator>Torsten.</dc:creator>
      <dc:date>2013-08-06T12:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160381#M485002</link>
      <description>&lt;P&gt;Hi Torsten ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;grep "Banne" /opt/ssh/etc/sshd_config&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Banner /home/test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;cat /home/test&lt;/P&gt;&lt;P&gt;test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and again when am trying telnet 10.xx.xx.xx 22 &amp;nbsp;from my local machine to this server am able to get the ssh version .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 12:53:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160381#M485002</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-06T12:53:52Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160409#M485003</link>
      <description>&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We need to change open ssh banner here.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need to edit this file as ;&lt;/P&gt;&lt;P&gt;Read in a forum .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;root #/ &amp;gt;vim /opt/ssh/src/ssh/version.h&lt;BR /&gt;/* $OpenBSD: version.h,v 1.48 2006/11/07 10:31:31 markus Exp $ */&lt;/P&gt;&lt;P&gt;#define SSH_VERSION "OpenSSH_4.5"&lt;/P&gt;&lt;P&gt;#ifdef HP_SFTP_UMASK_FIX&lt;BR /&gt;#define SSH_PORTABLE "p1+sftpfilecontrol-v1.1"&lt;BR /&gt;#else&lt;BR /&gt;#define SSH_PORTABLE "p1"&lt;BR /&gt;#endif /* HP_SFTP_UMASK_FIX */&lt;/P&gt;&lt;P&gt;#ifdef HP_HPN_PATCH&lt;BR /&gt;#define SSH_HPN "-hpn12v14"&lt;BR /&gt;#define SSH_RELEASE SSH_VERSION SSH_PORTABLE SSH_HPN&lt;BR /&gt;#else&lt;BR /&gt;#define SSH_RELEASE SSH_VERSION SSH_PORTABLE&lt;BR /&gt;#endif /* HP_HPN_PATCH */&lt;/P&gt;&lt;P&gt;#ifdef HP_VERSION_STRING /* Here: for hp ssh version */&lt;BR /&gt;#include "hp_version.h"&lt;BR /&gt;#endif /* HP_VERSION_STRING */&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2013 13:14:56 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6160409#M485003</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-06T13:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6161685#M485016</link>
      <description>&lt;P&gt;&lt;SPAN&gt;How to disable SSH version and Operating System banner ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;#telnet localhost 22&lt;BR /&gt;&lt;BR /&gt;OpenSSH 4.5p1sdtpfilecontrol-v1.1hpn12v14&lt;/PRE&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&lt;SPAN&gt;after a lot of research i have found that we cannot and should not disbale it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;since it is reqd for clients who connect this server.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2013 08:19:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6161685#M485016</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-07T08:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Version disclosure how to avoid it</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6168131#M485054</link>
      <description>&lt;P&gt;Hi Matti / Dennis ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Waiting for your suggestions.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Aug 2013 13:03:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/version-disclosure-how-to-avoid-it/m-p/6168131#M485054</guid>
      <dc:creator>chindi</dc:creator>
      <dc:date>2013-08-13T13:03:53Z</dc:date>
    </item>
  </channel>
</rss>

