Your message dated Fri, 1 Aug 2008 09:45:58 -0600
with message-id <[EMAIL PROTECTED]>
and subject line Re: Bug#282520: nmap: Use the SSH extended version string
(e.g. this is Debian 3.0r3 or better)
has caused the Debian Bug report #282520,
regarding nmap: Use the SSH extended version string (e.g. this is Debian 3.0r3
or better)
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)
--
282520: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=282520
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: nmap
Version: 3.55-0.backports.org.1
Severity: wishlist
Hi.
It would be nice if nmap -A and nmap -V took advantage of the extended
SSH version string. The full version string (probably parsed) should
appear in the -A listing, and -V could use it to guess the operating
system.
With Debian itself, we could lookup
/usr/share/doc/ssh/changelog.Debian.gz, and see this is the last patch
from Woody. We can determine whether the admin has the system patched
properly, or this is the last revision without the security.debian.org
updates, or some random testing version...
Example:
$ date -R
Mon, 22 Nov 2004 18:30:52 +0000
$ nc sco.com 22
SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1.woody.3
$ zcat /usr/share/doc/ssh/changelog.Debian.gz | head
openssh (1:3.4p1-1.woody.3) stable-security; urgency=high
* NMU by the security team.
* Apply additional realloc fixes from Solar Designer
* Apply double-free fix, taken from OpenBSD CVS
-- Wichert Akkerman <[EMAIL PROTECTED]> Fri, 19 Sep 2003 08:00:44 +0000
openssh (1:3.4p1-1.woody.2) stable-security; urgency=high
We can see SCO has a properly patched sshd from Debian Woody (Stable).
It's unclear whether the security updates are being applied properly; at
least we know they use the current (3rd) revision.
Cheers,
Jan.
-- System Information
Debian Release: 3.0
Architecture: i386
Kernel: Linux kontryhel 2.4.27-jan #5 Sat Aug 28 02:46:21 CEST 2004 i686
Locale: LANG=C, LC_CTYPE=cs_CZ.ISO-8859-2
Versions of packages nmap depends on:
ii libc6 2.2.5-11.5 GNU C Library: Shared libraries an
ii libpcre3 3.4-1.1 Philip Hazel's Perl Compatible Reg
ii libssl0.9.6 0.9.6c-2.woody.6 SSL shared libraries
ii libstdc++2.10-glibc2.2 1:2.95.4-11woody1 The GNU stdc++ library
pgpf4UuyXUkI8.pgp
Description: PGP signature
--- End Message ---
--- Begin Message ---
Version: 4.62-1
--
This was fixed sometime in or before 4.62-
lamont
--- End Message ---