3 ms·
While I mostly agree that the cries of "zomg security through obscurity" that one mostly sees on the internet these days come from people who are really just pa
by trotsky 15y ago
While I mostly agree that the cries of "zomg security through obscurity" that one mostly sees on the internet these days come from people who are really just parroting a catch phrase, one shouldn't forget that the industry came upon that aversion honestly. Mostly, it seems, the bad old days of raw security through obscurity are behind us. Examples like custom protocols substituting for authentication, proprietary encoding substituting for encryption, etc.
So it seems quite possible that those who might mock running ssh on a nonstandard port or omitting a service version might never have seen actual pure examples of the practice. Perhaps in some years "defense in depth" will have become such a saying that people relying solely on not having bugs in their application will get bullied in a similar way.
- tptacek 15y agoExploits don't care about version banners. You know what cares about version banners? Nessus. If blinding your own security scanners makes you feel better, go ahead, I guess.
- trotsky 15y agoBrowser exploit packs absolutely care about version numbers. It's how they determine what if any exploits to push to a client. Nessus, on the other hand, will never look at a user-agent string. So while you're probably correct for one class of threats and targets (targeted and enterprise servers) I wouldn't agree at all that the world is as black and white as you're claiming.
- tptacek 15y agoAre we talking about modifying your browser binary to defeat memory disclosure exploits? I didn't think we were talking about that.
- trotsky 15y agoIt certainly seems in scope to me if we're talking about version identifiers, and it (along with several other examples) are clear situations where changing an identifier string could definitely lead to an automated attack that would succeed never being tried. And you don't need to modify any binaries: The easiest way to change something like that is in a transparent proxy, but ie also supports changing via the registry, opera and firefox via about:config, etc.
- tptacek 15y agoWhat's an example of a serverside vulnerability that cares about version banners?
- trotsky 15y agoWhat vulnerability depends on a specific version banner? Surely you're not insisting that the actual bug be predicated on the fact that one version prints instead of another. A server intrusion work flow that involves a version banner? Saint on /24 -> choose exploit & target based on results. I understand you've said either this isn't worth the tradeoffs or 0days aren't getting mass exploited this way, but it is hard to believe you really disagree that intrusions happen in this fashion.
- tptacek 15y agoThat's how security consultants break into machines. If you're arguing that someone with a very recent SSH remote is going to use Saint to scope out a target, no; doubt it.
- spindritf 15y ago> it seems quite possible that those who might mock running ssh on a nonstandard port Running sshd on a nonstandard port is not a security measure, it keeps your logs cleaner and saves you a few cycles.
- tptacek 15y agoOk, see, that's a good reason to run SSH on a nonstandard port. Thank you.