From: Kevin Z. <kev...@gm...> - 2017-05-26 00:33:38
|
On 05/25/2017 17:04, li...@la... wrote: > sshguard 1.7 is not catching key exchange ssh hacks. The number of > fools attempting such a hack is small, but some are persistent. I've > been blocking them by hand. I can't reproduce your issue. Specifically, I checked out the 1.7.1 sshg-parser and ran: $ echo "May 24 20:37:06 theranch sshd[60250]: fatal: Unable to negotiate with 172.81.185.192 port 50267: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1 [preauth]" | sshg-parser And got an attack. -- Kevin Zheng kev...@gm... | ke...@be... | PGP: 0xC22E1090 |