Re: service version disclosure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Reindl Harald writes:



Am 07.01.2012 08:02, schrieb Digimer:
>> i know about the pros and cons for obscurity
>>
>> but i also know that from "SSH-2.0-OpenSSH_5.8" only "SSH-2.0"
>> is relevant for clients and having backports in mind this must
>> be the truth because if the whole version would matter all
>> LTS distributions would be broken by design
>
> This doesn't change the fundamental point;
>
> You are asking for a significant change in behaviour to a program that
> who-knows-how-many apps use, for no real reason other than to make a
> client feel better.

no, one keys of security is to provide as less informations as
absolutely necessary, not only for sshd, for every single
service

in the best case no single foreign person has an idea
what software you are currently running, not what OS
nor what service-software and at least no exact version

Ok, then why are you even running ssh on the default port?


Attachment: pgpJJXQ0YOZOK.pgp
Description: PGP signature

-- 
devel mailing list
devel@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/devel

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Fedora Announce]     [Fedora Kernel]     [Fedora Testing]     [Fedora Formulas]     [Fedora PHP Devel]     [Kernel Development]     [Fedora Legacy]     [Fedora Maintainers]     [Fedora Desktop]     [PAM]     [Red Hat Development]     [Gimp]     [Yosemite News]
  Powered by Linux