Mailinglist Archive: opensuse-security (685 mails)

< Previous Next >
Re: [suse-security] hacked??
  • From: Ben Rosenberg <ben@xxxxxxxxx>
  • Date: Tue, 19 Feb 2002 15:46:14 -0800
  • Message-id: <20020219234614.GF2650@xxxxxxxxx>
You have to edit your sshd config to just accept ssh2 connections and
then it will refuse ssh1 connections. :)

--
Protocol 2
--

The above line in the /etc/ssh/sshd_config will read Protocal 2,1 unless you
change it and it will accept either connection. I'm using OpenSSH
3.0.2p1..

Cheers!

* Michael Stern (mhstar@xxxxxx) [020219 15:38]:
->well at least you have a good chance that no real person attacked you and
->played around with your data but this was more like an automated attack ..
->something like codered =)
->
->http://it.mycareer.com.au/breaking/20010119/A14830-2001Jan19.html
->
->i heart that even the recent sshd versions fall back to ssh1 if the client
->requests them to do so .. but this doesn't mean they are vulnerable, does it?
->i disabled ssh1 anyway .. better safe than sorry ;-)

-----=====-----=====-----=====-----=====-----
Ben Rosenberg mailto:ben@xxxxxxxxx
-----=====-----=====-----=====-----=====-----
"I've never been quarantined. But the more I look around the more I
think it might not be a bad thing." -JC

< Previous Next >
Follow Ups
References