OpenSSH Protocol 1

"Denman, Tim \(Mission Systems\)" <[email protected]>
Newsgroups gmane.os.openbsd.www
Message-ID <[email protected]>
I've seen a lot of articles on this, but I'm very curious about the
vulnerability with OpenSSH protocol 1. The fix for us has been to
disable Protocol 1, however on a re-install of a newer version the
config will default back to Protocol 1.
	What is the latest version of OpenSSH where protocol 1 does not
have a vulnerability, or does this exist? If SRRs are run against a
particular system, no potential vulnerabilities are reported.  However,
Nessus reports a possible vulnerability.


Thanks for your help.

Tim Denman, CISSP


Tim Denman, CISSP
Specialty Engineering, Security
Northrop Grumman Mission Systems
213 Wynn Dr
Huntsville, AL 35805
Phone: 256-830-3587
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.