<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nessus Plugin ID 70658 &#8211; 21點情報網</title>
	<atom:link href="https://ailog.tw/lifelog/tag/nessus-plugin-id-70658/feed/" rel="self" type="application/rss+xml" />
	<link>https://ailog.tw/lifelog</link>
	<description></description>
	<lastBuildDate>Tue, 28 Sep 2021 07:10:34 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.3</generator>
	<item>
		<title>SSH服務被弱點掃描檢測出「SSH Server CBC Mode Ciphers Enabled」如何改善</title>
		<link>https://ailog.tw/lifelog/2021/09/28/ssh-server-cbc/</link>
		
		<dc:creator><![CDATA[blackjack]]></dc:creator>
		<pubDate>Tue, 28 Sep 2021 06:49:56 +0000</pubDate>
				<category><![CDATA[3C資訊]]></category>
		<category><![CDATA[FreeBSD]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[freebsd]]></category>
		<category><![CDATA[Nessus Plugin ID 70658]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[SSH Server CBC Mode Ciphers Enabled]]></category>
		<guid isPermaLink="false">https://ailog.tw/lifelog/?p=11195</guid>

					<description><![CDATA[相信越來越多單位被要求進行弱點掃描，而在Linux主機上常見的SSH弱點是「SSH Server CBC Mo &#8230; <p class="link-more"><a href="https://ailog.tw/lifelog/2021/09/28/ssh-server-cbc/" class="more-link">閱讀全文<span class="screen-reader-text">〈SSH服務被弱點掃描檢測出「SSH Server CBC Mode Ciphers Enabled」如何改善〉</span></a></p>]]></description>
										<content:encoded><![CDATA[<p><span style="font-size: 14pt; font-family: verdana, geneva;">相信越來越多單位被要求進行弱點掃描，而在Linux主機上常見的SSH弱點是「SSH Server CBC Mode Ciphers Enabled」，小編今天就來分享一下如何排除這個弱點。<span id="more-11195"></span></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">弱點掃描影響說明：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><a href="https://www.tenable.com/plugins/nessus/70658">https://www.tenable.com/plugins/nessus/70658</a></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">[範例情境]</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">01、作業系統為FreeBSD 12.2-RELEASE-p7</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">02、SSH版本為OpenSSH_7.9p1</span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">[操作步驟]</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">01、檢測SSH Server目前的設定</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">指令語法：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">sshd -T |grep ciphers</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img fetchpriority="high" decoding="async" class="alignnone wp-image-11198 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-01.png" alt="" width="683" height="93" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-01.png 683w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-01-300x41.png 300w" sizes="(max-width: 683px) 100vw, 683px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">02、變更設定</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">(1)、編輯設定檔<br />
指令語法：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">vi /etc/ssh/sshd_config<br />
<img decoding="async" class="alignnone wp-image-11199 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-02.png" alt="" width="407" height="72" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-02.png 407w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-02-300x53.png 300w" sizes="(max-width: 407px) 100vw, 407px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">(2)、修改設定參數</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">新增下列設定值</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">Ciphers aes128-ctr,aes192-ctr,aes256-ctr</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img decoding="async" class="alignnone wp-image-11200 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-03.png" alt="" width="431" height="181" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-03.png 431w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-03-300x126.png 300w" sizes="(max-width: 431px) 100vw, 431px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">03、重新啟動SSH服務<br />
指令語法：<br />
/etc/rc.d/sshd restart</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;"><img loading="lazy" decoding="async" class="alignnone wp-image-11201 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-04.png" alt="" width="468" height="152" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-04.png 468w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-04-300x97.png 300w" sizes="auto, (max-width: 468px) 100vw, 468px" /></span></p>
<p><span style="font-size: 14pt; font-family: verdana, geneva;">04、重新檢測SSH Server設定</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">指令語法：</span><br />
<span style="font-size: 14pt; font-family: verdana, geneva;">sshd -T |grep ciphers<br />
</span><img loading="lazy" decoding="async" class="alignnone wp-image-11205 size-full" src="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-05.png" alt="" width="409" height="87" srcset="https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-05.png 409w, https://ailog.tw/lifelog/wp-content/uploads/2021/09/ssh-server-cbc-05-300x64.png 300w" sizes="auto, (max-width: 409px) 100vw, 409px" /></p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
