Hiding SSH Host Banner Doesnt work

Damien Miller djm at mindrot.org
Wed Jun 17 10:27:42 AEST 2020


On Tue, 16 Jun 2020, bo0od wrote:

> maybe its useful but on the other hand its bad decision if user want to hide
> it in order to avoid bots attacks for vulnerable versions (for surely it
> should be left not updated for long time BUT still optional setting is
> preferable for the user to choose hide it or not)

I think you're misunderstanding how attacks work. Trying 10000 different
exploits against your sshd because the attacker doesn't know the version
is not perceptibly more difficult than trying a single one.


More information about the openssh-unix-dev mailing list