<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to disable ssh server version name and number? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355834#M903067</link>
    <description>&lt;P&gt;Thank you so much for the response. I have some question regarding your suggestion.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;How can I&amp;nbsp;&lt;SPAN&gt;re-compiled the ssh client binaries of IOS firmware.?&lt;BR /&gt;Could you please provide any guides for that? Or any CISCO custom binaries are available for the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please share it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Mar 2018 12:31:07 GMT</pubDate>
    <dc:creator>faizzaidi</dc:creator>
    <dc:date>2018-03-27T12:31:07Z</dc:date>
    <item>
      <title>How to disable ssh server version name and number?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355397#M903062</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am performing a switch hardening process. One of our clients has&amp;nbsp;an issue&amp;nbsp;with&amp;nbsp;&lt;SPAN&gt;Cisco 6500 switch.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;While performing a Nmap scan on our network. We get the following information as a result.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="cisco.png" style="width: 476px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/9414iD4818C7D13FEFAA7/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco.png" alt="cisco.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I would like to know this possible I can hide or remove or disable the Version information&amp;nbsp;from the switch i.e Cisco SSH 1.25(protocol 2.0).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:33:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355397#M903062</guid>
      <dc:creator>faizzaidi</dc:creator>
      <dc:date>2020-02-21T15:33:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable ssh server version name and number?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355774#M903066</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;
&lt;P&gt;This information is given up as part of normal ssh client operation. Run your SSH client with the verbose flag and you will see the information which is exchanged before authentication takes place:&lt;/P&gt;
&lt;PRE&gt;srupik@debian:~$ ssh -l srupik -v x.x.x.x
OpenSSH_7.4p1 Debian-10+deb9u3, OpenSSL 1.0.2l  25 May 2017
debug1: Reading configuration data /etc/ssh/ssh_config
...
debug1: Local version string SSH-2.0-OpenSSH_7.4p1 Debian-10+deb9u3
debug1: Remote protocol version 2.0, remote software version Cisco-1.25
debug1: match: Cisco-1.25 pat Cisco-1.* compat 0x60000000
...
password: &lt;/PRE&gt;
&lt;P&gt;...in short, you cannot stop this information from being revealed... unless perhaps you re-compiled the ssh client binaries which are running in the IOS firmware...!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You mat also like to read:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://nmap.org/book/vscan.html" target="_blank"&gt;https://nmap.org/book/vscan.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 10:33:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355774#M903066</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2018-03-27T10:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable ssh server version name and number?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355834#M903067</link>
      <description>&lt;P&gt;Thank you so much for the response. I have some question regarding your suggestion.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;How can I&amp;nbsp;&lt;SPAN&gt;re-compiled the ssh client binaries of IOS firmware.?&lt;BR /&gt;Could you please provide any guides for that? Or any CISCO custom binaries are available for the issue.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please share it.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 12:31:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3355834#M903067</guid>
      <dc:creator>faizzaidi</dc:creator>
      <dc:date>2018-03-27T12:31:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to disable ssh server version name and number?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3356487#M903069</link>
      <description>&lt;P&gt;My suggestion was hypothetical. The IOS code is propriety, you would not be able to compile and re-bundle it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You will have to live with the fact that IOS will leak information about the versions of some of its services. The best you can do is to run the latest IOS version which mitigates the current set of vulnerabilities which may affect those services.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers,&lt;/P&gt;
&lt;P&gt;Seb.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Mar 2018 09:14:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-disable-ssh-server-version-name-and-number/m-p/3356487#M903069</guid>
      <dc:creator>Seb Rupik</dc:creator>
      <dc:date>2018-03-28T09:14:50Z</dc:date>
    </item>
  </channel>
</rss>

