[j-nsp] SSH version 4 vulnerability on JUNOS

2013-09-09 Thread Harri Makela
Hi There I got following report from after the vulneraboility scanning. Now first we don`t use IPv6 and secondly how we can check on Juniper that versio is SSH 4? Synopsis: The remote SSH service is prone to an X11 session hijacking\nvulnerability. Description:  According to its banner, the

Re: [j-nsp] SSH version 4 vulnerability on JUNOS

2013-09-09 Thread Tim Eberhard
I've checked in with Juniper CERT a couple of times after SSH vulnerabilities get made public and given the fact they run such older ssh binaries. The answer i've received every time is they run a modified version of OpenSSH 4.4, and disallow unsigned, third party or modified binaries to run

Re: [j-nsp] SSH version 4 vulnerability on JUNOS

2013-09-09 Thread Harri Makela
version 4 vulnerability on JUNOS I've checked in with Juniper CERT a couple of times after SSH vulnerabilities get made public and given the fact they run such older ssh binaries.  The answer i've received every time is they run a modified version of OpenSSH  4.4, and disallow unsigned, third