Files
nuclei-templates/file/audit/ssh/file-disable-ssh-protocol.yaml

32 lines
1.1 KiB
YAML
Raw Normal View History

2025-03-10 16:27:28 +05:30
id: file-disable-sshp-protocol
2024-08-31 17:19:05 +05:30
info:
2025-03-10 16:27:28 +05:30
name: Disable SSH Protocol
2024-08-31 17:19:05 +05:30
author: pussycat0x
2025-02-06 16:24:12 +05:30
severity: unknown
2024-08-31 17:19:05 +05:30
description: |
2025-02-07 16:22:32 +05:30
Using SSH Protocol 1 is insecure as it lacks strong encryption and integrity checks, making it vulnerable to man-in-the-middle attacks, session hijacking, and other exploits. It is recommended to use SSH Protocol 2 for enhanced security.
2024-08-31 17:19:05 +05:30
remediation: |
2025-02-10 16:16:11 +05:30
Set Protocol 2 in /etc/ssh/sshd_config to disable SSH Protocol 1 and restart the SSH service.
2024-08-31 17:19:05 +05:30
reference:
- https://vishalraj82.medium.com/hardening-openssh-security-37f5d634015f
- https://www.ktchost.com/blog/enable-ssh-protocol-2/
2025-02-10 16:16:11 +05:30
metadata:
verified: true
2024-08-31 17:19:05 +05:30
tags: audit,config,file,ssh
file:
- extensions:
- all
2025-02-06 16:24:12 +05:30
matchers-condition: and
2024-08-31 17:19:05 +05:30
matchers:
2025-02-06 16:24:12 +05:30
- type: word
words:
- "# This is the sshd server system-wide configuration file"
2024-08-31 17:19:05 +05:30
- type: word
words:
- "Protocol 2"
2025-02-24 06:07:14 +00:00
negative: true
2025-03-10 11:01:42 +00:00
# digest: 4b0a00483046022100df321d349e00834fe6ee106774d32184d6aeec1c921f5c7bbbe76fe436bbf86202210098eb1f0ac12461bbda59911610b7fec2f6a87c5f808390253ae4aa05b52a8012:922c64590222798bb761d5b6d8e72950