You are not logged in.

#1 2009-01-01 19:40:28

anrxc
Member
From: Croatia
Registered: 2008-03-22
Posts: 834
Website

OpenSSH 5.1 banner

Anyone knows what happened between openssh 5.0 and 5.1 regarding the picture. OpenSSH changelog didn't offer much clues.

sshclientit8.th.png


You need to install an RTFM interface.

Offline

#2 2009-01-02 11:48:09

rson451
Member
From: Annapolis, MD USA
Registered: 2007-04-15
Posts: 1,233
Website

Re: OpenSSH 5.1 banner


archlinux - please read this and this — twice — then ask questions.
--
http://rsontech.net | http://github.com/rson

Offline

#3 2009-01-02 17:09:51

anrxc
Member
From: Croatia
Registered: 2008-03-22
Posts: 834
Website

Re: OpenSSH 5.1 banner

Ofcourse, but what about OpenSSH 5.1 client?


You need to install an RTFM interface.

Offline

#4 2009-01-02 17:13:43

rson451
Member
From: Annapolis, MD USA
Registered: 2007-04-15
Posts: 1,233
Website

Re: OpenSSH 5.1 banner

That is the client.  I can ssh to localhost with it and it still works.


archlinux - please read this and this — twice — then ask questions.
--
http://rsontech.net | http://github.com/rson

Offline

#5 2009-01-02 18:47:49

anrxc
Member
From: Croatia
Registered: 2008-03-22
Posts: 834
Website

Re: OpenSSH 5.1 banner

That is the client.

All I saw was putty.

I can ssh to localhost with it and it still works.

So it works for you, and for everyone else it appears for I wasn't able to find one mention of this. I have a Slackware machine with 5.0 and there it works while on Arch with 5.1 it doesn't. It stopped working some 6 months ago, with the upgrade from 5.0.


You need to install an RTFM interface.

Offline

#6 2009-01-03 17:58:39

anrxc
Member
From: Croatia
Registered: 2008-03-22
Posts: 834
Website

Re: OpenSSH 5.1 banner

I was wrong, I'm not the only person to notice this. Newer Slackware versions also have OpenSSH 5.1 and I found a topic where some fellow makes inquiries about this http://www.linuxquestions.org/questions … ns-663495/

There they refer to LFS documentation http://www.linuxfromscratch.org/blfs/vi … logon.html where is said that certain escape sequences in issue.net will not be interpreted (the ones that are interpreted on login from /etc/issue)... but this was always true, while colors worked.

Then I went on to read ssh rfc's and found:

5.4.  Banner Message

...

   The SSH server may send an SSH_MSG_USERAUTH_BANNER message at any
   time after this authentication protocol starts and before
   authentication is successful.  This message contains text to be
   displayed to the client user before authentication is attempted.  The
   format is as follows:

      byte      SSH_MSG_USERAUTH_BANNER
      string    message in ISO-10646 UTF-8 encoding [RFC3629]
      string    language tag [RFC3066]

...

   If the 'message' string is displayed, control character filtering,
   discussed in [SSH-ARCH], SHOULD be used to avoid attacks by sending
   terminal control characters.

...

[SSH-ARCH]
9.2.  Control Character Filtering

   When displaying text to a user, such as error or debug messages, the
   client software SHOULD replace any control characters (except tab,
   carriage return, and newline) with safe sequences to avoid attacks by
   sending terminal control characters.

If there was a change in 5.1 and filtering - it wasn't documented in the Changelog. I'm certainly not the only person with a colored banner and I expected that more people will ask about this, but 6 months later there was none of it so I decided to post here.


You need to install an RTFM interface.

Offline

#7 2009-09-29 21:55:24

PiousMinion
Member
Registered: 2009-07-21
Posts: 12

Re: OpenSSH 5.1 banner

So....
Has no one found a workaround for this?

I want a warning/message BEFORE they gain access to my system.  While having color is preferable, this limitation also impacts my ability to include my message in other languages.

The banner I'm trying to get working correctly can be found here: http://bbs.archlinux.org/viewtopic.php? … 09#p619409
Try it out for yourself and see how mangled the entire thing looks due to the other languages.

Offline

Board footer

Powered by FluxBB