Subject: Re: sha1 hash is incorrect

Re: sha1 hash is incorrect

From: Daniel Stenberg <daniel_at_haxx.se>
Date: Sun, 13 Jun 2010 23:39:42 +0200 (CEST)

On Sun, 13 Jun 2010, Aris Adamantiadis wrote:

Please don't top-post, it breaks threading and makes discussions hard to
follow.

> According to SSH-2 specs, SSH-1.99-* banners announce a server
> compatible with both SSH2 and SSH1.

I was looking for this in the specs, where exactly does it say this?

> What's more plausible is that freessh uses (maybe introducing bugs) ciphers
> and hashs that were not fully tested within libssh2.

Perhaps. But since the server in question is documented to only speak SSH 1.5,
it is also very likely that the server simply doesn't speak SSH2 properly.

I guess one way to find out is to either read the Fressh source code or
possiblt set one up to run tests against. Their official web site at
http://www.fressh.org seems to be dead. The most recent version I could find
using archive.org is from 2005[*]. It makes me suspect this software is not
very actively maintained...

I downloaded the latest version I found on archive.org (0.8.1), and it failed
to compile pretty badly so I don't consider it a worthwhile effort to go down
that path.

Until we see a problem with a different server, I will remain suspecting this
is a problem related to Fressh.

[*] = http://web.archive.org/web/20050407081110/http://www.fressh.org/

-- 
  / daniel.haxx.se
_______________________________________________
libssh2-devel http://cool.haxx.se/cgi-bin/mailman/listinfo/libssh2-devel
Received on 2010-06-13