Hiding SSH Host Banner Doesnt work
Damien Miller
djm at mindrot.org
Wed Jun 17 10:27:42 AEST 2020
On Tue, 16 Jun 2020, bo0od wrote:
> maybe its useful but on the other hand its bad decision if user want to hide
> it in order to avoid bots attacks for vulnerable versions (for surely it
> should be left not updated for long time BUT still optional setting is
> preferable for the user to choose hide it or not)
I think you're misunderstanding how attacks work. Trying 10000 different
exploits against your sshd because the attacker doesn't know the version
is not perceptibly more difficult than trying a single one.
More information about the openssh-unix-dev
mailing list