This is our old Q&A Site. Please post any new questions and answers at ask.wireshark.org.

Hi All,

When I capture the packets for SFTP transfer, we notice in the packet from server "server protocol: SSH-2.0-openssh_4.0" but when we check under the protocol in the wireshark, it is showing as SSH and not sshv2.

Is it not Version2? (From the server Protocol?)

How is Wireshark deoding it as sshv1 or SSHv2? This is the packet after the 3 way handshake received from the server.

asked 22 Sep '17, 00:46

rakeshreddy's gravatar image

rakeshreddy
5346
accept rate: 0%

What Wireshark version are you using? Can you share a capture in a publicly accessible spot, e.g. CloudShark?

(22 Sep '17, 02:28) Jaap ♦
Be the first one to answer this question!
toggle preview

Follow this question

By Email:

Once you sign in you will be able to subscribe for any updates here

By RSS:

Answers

Answers and Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "title")
  • image?![alt text](/path/img.jpg "title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Question tags:

×8

question asked: 22 Sep '17, 00:46

question was seen: 1,688 times

last updated: 22 Sep '17, 02:28

p​o​w​e​r​e​d by O​S​Q​A