Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Hiding version of Apache and OpenSSH from port scanners.
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
exklusve
Apprentice
Apprentice


Joined: 23 Aug 2002
Posts: 270
Location: currently ~/

PostPosted: Thu Nov 21, 2002 10:38 pm    Post subject: Hiding version of Apache and OpenSSH from port scanners. Reply with quote

If I run a port scan on my Gentoo box, I can see the versions of Apache and SSH I'm running. Even the mod_ssl.
Is there a way to make Apache and SSL not show this info??

I would really like to get rid of that. Just a few things I dont want advertised on my box.
Thanks!!
_________________
eXklusve

You do know that no one gives a shit about your system spec's right?
Back to top
View user's profile Send private message
rac
Bodhisattva
Bodhisattva


Joined: 30 May 2002
Posts: 6553
Location: Japanifornia

PostPosted: Thu Nov 21, 2002 11:32 pm    Post subject: Reply with quote

How about "ServerTokens prod"?
_________________
For every higher wall, there is a taller ladder
Back to top
View user's profile Send private message
exklusve
Apprentice
Apprentice


Joined: 23 Aug 2002
Posts: 270
Location: currently ~/

PostPosted: Thu Nov 21, 2002 11:34 pm    Post subject: Hiding version of Apache and OpenSSH from port scanners. Reply with quote

I'm sorry I dont follow.
_________________
eXklusve

You do know that no one gives a shit about your system spec's right?
Back to top
View user's profile Send private message
exklusve
Apprentice
Apprentice


Joined: 23 Aug 2002
Posts: 270
Location: currently ~/

PostPosted: Thu Nov 21, 2002 11:36 pm    Post subject: Hiding version of Apache and OpenSSH from port scanners. Reply with quote

oops. I know what you are talking about. i'll look it up on google.
and post any findings.
Thanx!!
_________________
eXklusve

You do know that no one gives a shit about your system spec's right?
Back to top
View user's profile Send private message
rac
Bodhisattva
Bodhisattva


Joined: 30 May 2002
Posts: 6553
Location: Japanifornia

PostPosted: Thu Nov 21, 2002 11:36 pm    Post subject: Reply with quote

http://httpd.apache.org/docs/mod/core.html#servertokens
_________________
For every higher wall, there is a taller ladder
Back to top
View user's profile Send private message
exklusve
Apprentice
Apprentice


Joined: 23 Aug 2002
Posts: 270
Location: currently ~/

PostPosted: Thu Nov 21, 2002 11:49 pm    Post subject: Hiding version of Apache and OpenSSH from port scanners. Reply with quote

I added this to my
/etc/apache/conf/apache.conf

Code:
ServerTokens Prod

and now theres no version for apache.
Now to just get that working on SSH 8)
thanx!!
_________________
eXklusve

You do know that no one gives a shit about your system spec's right?
Back to top
View user's profile Send private message
purecaca
n00b
n00b


Joined: 10 Jul 2002
Posts: 10
Location: Denmark

PostPosted: Sat Jan 04, 2003 1:38 am    Post subject: openssh cant work without that info Reply with quote

openssh cant work without that information available, someone suggested a patch to remove the version info on the www.openssh.org 's maillinglist, and where told it wasnt posible
Back to top
View user's profile Send private message
rtn
Guru
Guru


Joined: 15 Nov 2002
Posts: 427

PostPosted: Mon Jan 06, 2003 6:29 am    Post subject: Re: openssh cant work without that info Reply with quote

purecaca wrote:
openssh cant work without that information available, someone suggested a patch to remove the version info on the www.openssh.org 's maillinglist, and where told it wasnt posible


At a previous job, we examined that, and found that we could alter the
ssh version string in the source without breaking anything. It was a long
time ago, so you'd have to do your own testing but it worked just fine when
we did it a couple of years ago.

--rtn
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum