Author: Damien MillerDamien Miller
Date: Apr 24, 2008 00:49
On Tue, 22 Apr 2008, sricci wrote:
> hi,
>
> what's your opinion about OpenSSH hideversion.patch ? (it is a
> patch for hide the version of sshd service )
Pointless, if not harmful.
It breaks bug compatibility and provides only a psychological security
benefit. It doesn't cost an attacker much to spam all their known
exploits at a service, regardless of what version it reports.
|