Discussion:
<None>
(too old to reply)
Bob Koehler
2007-08-30 18:14:16 UTC
Permalink
Due to lack of funds we have some systems still running Multinet 4.4.
In order to support SSH we've applied the SSH ECOs, I think up to
the last that shipped for SSH under 4.4.

My VAXen, running VMS 5.5-2 and 6.1, and my Alpha running 7.2-1
were recently scanned and ticketed for providing SSH1.

I verified that SSH1 is not enabled in the configuration and that
attempts to connect using SSH1 are rejected.

The network security fellow I talked to seemed to agree they've got a
false positive (OBTW, thier records showed that the system was running
UNIX), but claims that the system may be "broadcasting" that it supports
SSH1.

I've no idea what he means by "broadcasting" this information and
whether I can turn that off. Any ideas?
Richard Whalen
2007-08-31 14:14:31 UTC
Permalink
What to you get when you TELNET to the port (typically 22) that SSH is
running on?

Is it a string like this:

SSH-1.99-3.2.9 F-SECURE SSH 5.0.1 - Process Software MultiNet

Well, that says that the system offers SSH1.

Even with SSH1 disabled MultiNet will put out a banner line saying that it
supports SSH1. When the client attempts to negotiate SSH1 service it will
find out that it really isn't supported.

The scanner is complaining about the plain text line that is exchanged after
the connection is made.
Post by Bob Koehler
Due to lack of funds we have some systems still running Multinet 4.4.
In order to support SSH we've applied the SSH ECOs, I think up to
the last that shipped for SSH under 4.4.
My VAXen, running VMS 5.5-2 and 6.1, and my Alpha running 7.2-1
were recently scanned and ticketed for providing SSH1.
I verified that SSH1 is not enabled in the configuration and that
attempts to connect using SSH1 are rejected.
The network security fellow I talked to seemed to agree they've got a
false positive (OBTW, thier records showed that the system was running
UNIX), but claims that the system may be "broadcasting" that it supports
SSH1.
I've no idea what he means by "broadcasting" this information and
whether I can turn that off. Any ideas?
Bob Koehler
2007-08-31 16:48:05 UTC
Permalink
Post by Richard Whalen
SSH-1.99-3.2.9 F-SECURE SSH 5.0.1 - Process Software MultiNet
SSH-2.0-3.2.9 F-SECURE SSH 5.0.1 - Process Software MultiNet

Loading...