Display Filter Reference: SSH Protocol

Protocol field name: ssh

Versions: 1.0.0 to 2.6.3

Back to Display Filter Reference

Field name Description Type Versions
ssh.compression_algorithms_client_to_server compression_algorithms_client_to_server string Character string 1.0.0 to 2.6.3
ssh.compression_algorithms_client_to_server_length compression_algorithms_client_to_server length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.compression_algorithms_server_to_client compression_algorithms_server_to_client string Character string 1.0.0 to 2.6.3
ssh.compression_algorithms_server_to_client_length compression_algorithms_server_to_client length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.cookie Cookie Sequence of bytes 1.0.0 to 2.6.3
ssh.dh.e DH client e Sequence of bytes 1.2.0 to 2.6.3
ssh.dh.f DH server f Sequence of bytes 1.2.0 to 2.6.3
ssh.dh.g DH base (G) Sequence of bytes 1.2.0 to 2.2.17
ssh.dh.p DH modulus (P) Sequence of bytes 1.2.0 to 2.2.17
ssh.dh_gex.g DH GEX base (G) Sequence of bytes 2.4.0 to 2.6.3
ssh.dh_gex.max DH GEX Max Unsigned integer, 4 bytes 1.2.0 to 2.6.3
ssh.dh_gex.min DH GEX Min Unsigned integer, 4 bytes 1.2.0 to 2.6.3
ssh.dh_gex.nbits DH GEX Number of Bits Unsigned integer, 4 bytes 1.2.0 to 2.6.3
ssh.dh_gex.p DH GEX modulus (P) Sequence of bytes 2.4.0 to 2.6.3
ssh.ecdh.q_c ECDH client\'s ephemeral public key (Q_C) Sequence of bytes 2.4.0 to 2.6.3
ssh.ecdh.q_c_length ECDH client\'s ephemeral public key length Unsigned integer, 4 bytes 2.4.0 to 2.6.3
ssh.ecdh.q_s ECDH server\'s ephemeral public key (Q_S) Sequence of bytes 2.4.0 to 2.6.3
ssh.ecdh.q_s_length ECDH server\'s ephemeral public key length Unsigned integer, 4 bytes 2.4.0 to 2.6.3
ssh.encrypted_packet Encrypted Packet Sequence of bytes 1.0.0 to 2.6.3
ssh.encryption_algorithms_client_to_server encryption_algorithms_client_to_server string Character string 1.0.0 to 2.6.3
ssh.encryption_algorithms_client_to_server_length encryption_algorithms_client_to_server length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.encryption_algorithms_server_to_client encryption_algorithms_server_to_client string Character string 1.0.0 to 2.6.3
ssh.encryption_algorithms_server_to_client_length encryption_algorithms_server_to_client length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.first_kex_packet_follows First KEX Packet Follows Unsigned integer, 1 byte 2.4.0 to 2.6.3
ssh.host_key.data Host key data Sequence of bytes 2.2.0 to 2.6.3
ssh.host_key.dsa.g DSA subgroup generator (g) Sequence of bytes 2.4.0 to 2.6.3
ssh.host_key.dsa.p DSA prime modulus (p) Sequence of bytes 2.4.0 to 2.6.3
ssh.host_key.dsa.q DSA prime divisor (q) Sequence of bytes 2.4.0 to 2.6.3
ssh.host_key.dsa.y DSA public key (y) Sequence of bytes 2.4.0 to 2.6.3
ssh.host_key.ecdsa.id ECDSA elliptic curve identifier Character string 2.4.0 to 2.6.3
ssh.host_key.ecdsa.id_length ECDSA elliptic curve identifier length Unsigned integer, 4 bytes 2.4.0 to 2.6.3
ssh.host_key.ecdsa.q ECDSA public key (Q) Sequence of bytes 2.4.0 to 2.6.3
ssh.host_key.ecdsa.q_length ECDSA public key length Unsigned integer, 4 bytes 2.4.0 to 2.6.3
ssh.host_key.length Host key length Unsigned integer, 4 bytes 2.2.0 to 2.6.3
ssh.host_key.rsa.e RSA public exponent (e) Sequence of bytes 2.2.0 to 2.6.3
ssh.host_key.rsa.n RSA modulus (N) Sequence of bytes 2.2.0 to 2.6.3
ssh.host_key.type Host key type Character string 2.2.0 to 2.6.3
ssh.kex.first_packet_follows KEX First Packet Follows Unsigned integer, 1 byte 1.2.0 to 2.2.17
ssh.kex.h_sig KEX H signature Sequence of bytes 2.4.0 to 2.6.3
ssh.kex.h_sig_length KEX H signature length Unsigned integer, 4 bytes 2.4.0 to 2.6.3
ssh.kex.reserved Reserved Sequence of bytes 1.2.0 to 2.6.3
ssh.kex_algorithms kex_algorithms string Character string 1.0.0 to 2.6.3
ssh.kex_algorithms_length kex_algorithms length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.kexdh.h_sig KEX DH H signature Sequence of bytes 1.2.0 to 2.2.17
ssh.kexdh.h_sig_length KEX DH H signature length Unsigned integer, 4 bytes 1.2.0 to 2.2.17
ssh.kexdh.host_key KEX DH host key Sequence of bytes 1.2.0 to 2.2.17
ssh.kexdh.host_key_length KEX DH host key length Unsigned integer, 4 bytes 1.2.0 to 2.0.16
ssh.languages_client_to_server languages_client_to_server string Character string 1.0.0 to 2.6.3
ssh.languages_client_to_server_length languages_client_to_server length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.languages_server_to_client languages_server_to_client string Character string 1.0.0 to 2.6.3
ssh.languages_server_to_client_length languages_server_to_client length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.mac MAC Sequence of bytes 1.2.0 to 2.6.3
ssh.mac_algorithms_client_to_server mac_algorithms_client_to_server string Character string 1.0.0 to 2.6.3
ssh.mac_algorithms_client_to_server_length mac_algorithms_client_to_server length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.mac_algorithms_server_to_client mac_algorithms_server_to_client string Character string 1.0.0 to 2.6.3
ssh.mac_algorithms_server_to_client_length mac_algorithms_server_to_client length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.mac_string MAC String Character string 1.0.0 to 1.0.16
ssh.message_code Message Code Unsigned integer, 1 byte 1.0.0 to 2.6.3
ssh.mpint_length Multi Precision Integer Length Unsigned integer, 4 bytes 1.2.0 to 2.6.3
ssh.packet_length Packet Length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
ssh.packet_length.error Overly large number Label 1.12.0 to 2.6.3
ssh.packet_length_encrypted Packet Length (encrypted) Sequence of bytes 1.12.0 to 2.6.3
ssh.padding_length Padding Length Unsigned integer, 1 byte 1.0.0 to 2.6.3
ssh.padding_string Padding String Sequence of bytes 1.0.0 to 2.6.3
ssh.payload Payload Sequence of bytes 1.0.0 to 2.6.3
ssh.protocol Protocol Character string 1.0.0 to 2.6.3
ssh.server_host_key_algorithms server_host_key_algorithms string Character string 1.0.0 to 2.6.3
ssh.server_host_key_algorithms_length server_host_key_algorithms length Unsigned integer, 4 bytes 1.0.0 to 2.6.3
Go Beyond with Riverbed Technology

Riverbed is Wireshark's primary sponsor and provides our funding. They also make great products that fully integrate with Wireshark.

I have a lot of traffic...

ANSWER: SteelCentral™ Packet Analyzer PE
  • • Visually rich, powerful LAN analyzer
  • • Quickly access very large pcap files
  • • Professional, customizable reports
  • • Advanced triggers and alerts
Learn More

Buy Now

No, really, I have a LOT of traffic…

ANSWER: SteelCentral™ AppResponse 11
  • • Full stack analysis – from packets to pages
  • • Rich performance metrics & pre-defined insights for fast problem identification/resolution
  • • Modular, flexible solution for deeply-analyzing network & application performance
Learn More