[Bro-Dev] [JIRA] (BIT-1518) SSH analyzer doesn't handle non-conformant client version strings

Vlad Grigorescu (JIRA) jira at bro-tracker.atlassian.net
Mon Jan 11 07:03:00 PST 2016


Vlad Grigorescu created BIT-1518:
------------------------------------

             Summary: SSH analyzer doesn't handle non-conformant client version strings
                 Key: BIT-1518
                 URL: https://bro-tracker.atlassian.net/browse/BIT-1518
             Project: Bro Issue Tracker
          Issue Type: Problem
          Components: Bro
    Affects Versions: 2.4
            Reporter: Vlad Grigorescu
            Assignee: Vlad Grigorescu


Received a report that some SSH clients send a version identification string similar to 'SSH-2.0-FooBar_Client\n' which causes a protocol violation in the SSH analyzer. RFC 4253 states that this must be terminated by '\r\n', but that's not what's being observed.



--
This message was sent by Atlassian JIRA
(v7.1.0-OD-04-012#71001)


More information about the bro-dev mailing list