Re: [Proftpd-user] Sftpcipher directive

Chris Young <[email protected]> Mon, 12 Aug 2024 16:00:14 -0500
Newsgroups gmane.network.proftpd.user
Message-ID <CABr7rqPqty-Rv7_6LED_wZs+t+t0kese+-iG572xd4CXsJcPrw@mail.gmail.com>
--===============4428725861340375932==
Content-Type: multipart/alternative; boundary="00000000000031383f061f82c9ae"

--00000000000031383f061f82c9ae
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

I don't use root when I run nmap
nmap -Pn --script ssh2-enum-algos -p 22 my.sftp.server

Root is only necessary if you're doing silly things with raw sockets.
Checking an sftp server for supported algos is basic tcp stuff.
No root required.

On Mon, Aug 12, 2024 at 12:28=E2=80=AFPM Geoffrey Myers <lists@serioustechn=
ology.com>
wrote:

> thanks Chris,
>
> If I recall correctly, map requires root access?  I don=E2=80=99t have ro=
ot
> access.  Is there any way to determine the altos/ciphers supported by
> proftpd that does not require root access?
>
>
> On Aug 2, 2024, at 10:38 PM, Chris Young <[email protected]> wrote:
>
> to "visualize" the enabled ciphers for your server, install nmap, and fro=
m
> a command line, you can run
>
> ## check for ssh/sftp algos
> nmap -Pn --script ssh2-enum-algos -p 22 SFTP.HOST.WHATEVER
>
> ## check for ssl/tls ciphers
> nmap --script ssl-enum-ciphers -p 443 WWW.HOST.WHATEVER
>
> if your machine is running openssl v3+, you'll get an accurate map of the
> enable key exchange and encryption algorithms.
>
> .. pretty sure ssh will show accurate, even for openssl v1, but modern tl=
s
> ciphers will only show if you have openssl v3+
>
>
> On Fri, Aug 2, 2024 at 1:36=E2=80=AFPM TJ Saunders <[email protected]> wro=
te:
>
>> > TJ, thanks.  Quick question.  I=E2=80=99m a bit confused.  As I refere=
nced ssh
>> > you mentioned  openssl. Does ssh use OpenSSL? I would expect openssh.
>>
>> The mod_sftp module for ProFTPD implements the SSH and SFTP protocols
>> using the OpenSSL library for the necessary cryptographic support.  It d=
oes
>> not use the OpenSSH implementations in any way.  In fact, mod_sftp
>> implements some parts of the SFTP protocol that OpenSSH does not impleme=
nt.
>>
>> Cheers,
>> TJ
>>
>>
>> _______________________________________________
>> ProFTPD Users List   <[email protected]>
>> Unsubscribe problems?
>> http://www.proftpd.org/list-unsub.html
>
> _______________________________________________
> ProFTPD Users List   <[email protected]>
> Unsubscribe problems?
> http://www.proftpd.org/list-unsub.html
>
>
> --
> Until later, Geof
>
>
>
> _______________________________________________
> ProFTPD Users List   <[email protected]>
> Unsubscribe problems?
> http://www.proftpd.org/list-unsub.html

--00000000000031383f061f82c9ae
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div><div><div>I don&#39;t use root when I run nmap<br><sp=
an style=3D"font-family:monospace">nmap -Pn --script ssh2-enum-algos -p 22 =
my.sftp.server</span><br><br></div>Root is only necessary if you&#39;re doi=
ng silly things with raw sockets.<br></div>Checking an sftp server for supp=
orted algos is basic tcp stuff.<br></div>No root required.<br></div><br><di=
v class=3D"gmail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Mon, Aug 1=
2, 2024 at 12:28=E2=80=AFPM Geoffrey Myers &lt;<a href=3D"mailto:lists@seri=
oustechnology.com">[email protected]</a>&gt; wrote:<br></div><blo=
ckquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left=
:1px solid rgb(204,204,204);padding-left:1ex"><div style=3D"overflow-wrap: =
break-word;">thanks Chris,<div><br></div><div>If I recall correctly, map re=
quires root access?=C2=A0 I don=E2=80=99t have root access.=C2=A0 Is there =
any way to determine the altos/ciphers supported by proftpd that does not r=
equire root access?</div><div><br><div><br><blockquote type=3D"cite"><div>O=
n Aug 2, 2024, at 10:38 PM, Chris Young &lt;<a href=3D"mailto:mrvjtod@gmail=
.com" target=3D"_blank">[email protected]</a>&gt; wrote:</div><br><div><div=
 dir=3D"ltr"><div><div>to &quot;visualize&quot; the enabled ciphers for you=
r server, install nmap, and from a command line, you can run</div><div styl=
e=3D"margin-left:40px"><span style=3D"font-family:monospace"><br>## check f=
or ssh/sftp algos<br></span></div><div style=3D"margin-left:40px"><span sty=
le=3D"font-family:monospace">nmap -Pn --script ssh2-enum-algos -p 22 SFTP.H=
OST.WHATEVER<br><br></span></div><div style=3D"margin-left:40px"><span styl=
e=3D"font-family:monospace">## check for ssl/tls ciphers<br></span></div><d=
iv style=3D"margin-left:40px"><span style=3D"font-family:monospace">nmap --=
script ssl-enum-ciphers -p 443 <a href=3D"http://WWW.HOST.WHATEVER" target=
=3D"_blank">WWW.HOST.WHATEVER</a><br></span></div><span style=3D"font-famil=
y:monospace"><br></span></div><div><span style=3D"font-family:arial,sans-se=
rif">if your machine is running openssl v3+, you&#39;ll get an accurate map=
 of the enable key exchange and encryption algorithms.</span></div><br><div=
>.. pretty sure ssh will show accurate, even for openssl v1, but modern tls=
 ciphers will only show if you have openssl v3+<br></div><div><br><span sty=
le=3D"font-family:arial,sans-serif"></span></div></div><br><div class=3D"gm=
ail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Aug 2, 2024 at 1:3=
6=E2=80=AFPM TJ Saunders &lt;<a href=3D"mailto:[email protected]" target=3D"=
_blank">[email protected]</a>&gt; wrote:<br></div><blockquote class=3D"gmail=
_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204=
,204);padding-left:1ex">&gt; TJ, thanks.=C2=A0 Quick question.=C2=A0 I=E2=
=80=99m a bit confused.=C2=A0 As I referenced ssh <br>
&gt; you mentioned=C2=A0 openssl. Does ssh use OpenSSL? I would expect open=
ssh. <br>
<br>
The mod_sftp module for ProFTPD implements the SSH and SFTP protocols using=
 the OpenSSL library for the necessary cryptographic support.=C2=A0 It does=
 not use the OpenSSH implementations in any way.=C2=A0 In fact, mod_sftp im=
plements some parts of the SFTP protocol that OpenSSH does not implement.<b=
r>
<br>
Cheers,<br>
TJ<br>
<br>
<br>
_______________________________________________<br>
ProFTPD Users List=C2=A0 =C2=A0&lt;<a href=3D"mailto:proftpd-users@proftpd.=
org" target=3D"_blank">[email protected]</a>&gt;<br>
Unsubscribe problems?<br>
<a href=3D"http://www.proftpd.org/list-unsub.html" rel=3D"noreferrer" targe=
t=3D"_blank">http://www.proftpd.org/list-unsub.html</a></blockquote></div>
_______________________________________________<br>ProFTPD Users List =C2=
=A0=C2=A0&lt;<a href=3D"mailto:[email protected]" target=3D"_blank"=
>[email protected]</a>&gt;<br>Unsubscribe problems?<br><a href=3D"h=
ttp://www.proftpd.org/list-unsub.html" target=3D"_blank">http://www.proftpd=
.org/list-unsub.html</a></div></blockquote></div><br><div>
<span style=3D"border-collapse:separate;color:rgb(0,0,0);font-family:Helvet=
ica;font-style:normal;font-variant:normal;font-weight:normal;letter-spacing=
:normal;line-height:normal;text-indent:0px;text-transform:none;white-space:=
normal;word-spacing:0px"><div>--</div><div>Until later, Geof</div><div><br>=
</div></span><br>

</div>
<br></div></div>_______________________________________________<br>
ProFTPD Users List=C2=A0 =C2=A0&lt;<a href=3D"mailto:proftpd-users@proftpd.=
org" target=3D"_blank">[email protected]</a>&gt;<br>
Unsubscribe problems?<br>
<a href=3D"http://www.proftpd.org/list-unsub.html" rel=3D"noreferrer" targe=
t=3D"_blank">http://www.proftpd.org/list-unsub.html</a></blockquote></div>

--00000000000031383f061f82c9ae--


--===============4428725861340375932==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============4428725861340375932==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
ProFTPD Users List   <[email protected]>
Unsubscribe problems?
http://www.proftpd.org/list-unsub.html
--===============4428725861340375932==--