Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 11 of 11
  1. #1
    Member
    Join Date
    Aug 2001
    Posts
    173

    Default open SSH exploit

    http://www.debian.org/security/2002/dsa-134

    Are we OK from this?

    Craig
    Craig Robinson - UKDedicated LTD
    UK Dedicated Servers, Managed Dedicated Servers and Colocation at Centro, Hemel Hempstead.

  2. #2
    Member
    Join Date
    Aug 2001
    Posts
    839

    Default

    not really OK at all, actually.
    However, the peeps at openssh spawned their update that was scheduled for monday a bit earlier (HORRAY)

    http://www.openssh.com

    I'm assuming Darkorb is going to latch on to this as well- but for now just an FYI that is what's available!

    ..............................


    http://www.fastservers.net/

    travis@fastservers.net
    ..............................

  3. #3
    Member
    Join Date
    Aug 2001
    Posts
    839

    Default

    BTW a quick addendum:

    This is only somewhat effective on RH 7.1 and EARLIER boxes----- 7.2 and 7.3 should be safe out of the box, as I've heard from various authorities. Also, after speaking with bdraco earlier he decrees the entire RedHat genre invulnverable to this, though the openssh 3.4 rpms will be gracing the cpanel update scene starting very, very soon.

    I think RedHat is rpm-a-zizing the source as I type this, or perhaps it's released by now.

    obviously www.openssh.com has anything technical you might want to know about this...........
    ..............................


    http://www.fastservers.net/

    travis@fastservers.net
    ..............................

  4. #4
    zex
    zex is offline
    Member zex's Avatar
    Join Date
    Aug 2001
    Posts
    99

    Default

    There is no thing like totaly secured computer. I think that we all learn in last few day's that only way to secure box is to keep it updated.

    Many security &experts& are said that 32 bit unix-like servers are not affected with latest apache bug, and 24 hours after that we are witness of exploit for OpenBSD, OS that didn't have remote exploit for last 5 years in default installation.

    Also according to news on some hackers sites, same exploit for Solaris and Linux is also avaliable in underground....

    All this including latest ssh exploit leed us to only one conclusion:
    We must pay attention to security to protect our business at least from persons with &script kiddie& knowledge.

    Security is not cheep thing we all know that, but it's much cheeper than loosing confidental information or clients.
    Signed,
    Dzevad Hadzic

  5. #5
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    We also know one more thing... Bill Gates wants our business really bad.
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  6. #6
    Member
    Join Date
    Oct 2001
    Posts
    90

    Default

    Anyone know when DarkOrb will be releaseing an official updater/patch?
    Urban Weigl
    http://hostit365.com/

  7. #7
    bdraco
    Guest

    Default

    http://rhn.redhat.com/errata/RHSA-2002-127.html

    This patch should go in tonight or tomorrow if you have security updates on.

  8. #8
    Member mickalo's Avatar
    Join Date
    Apr 2002
    Location
    N.W. Iowa
    Posts
    753

    Default

    does this apply to RedHat/Linux 6.2 also ??

    thx's

    Thunder Rain Internet Publishing

    Providing Internet Solutions that work!
    Custom Perl and Database Programming

  9. #9
    Member rpmws's Avatar
    Join Date
    Aug 2001
    Location
    back woods of NC, USA
    Posts
    1,858

    Default

    [quote:522abbc6ac][i:522abbc6ac]Originally posted by bdraco[/i:522abbc6ac]

    http://rhn.redhat.com/errata/RHSA-2002-127.html

    This patch should go in tonight or tomorrow if you have security updates on.[/quote:522abbc6ac]

    Hey Nick .... THANKS MAN!!!!
    Just keeping my "eye" on things....
    R. Paul Mathews
    RPMWS - diehard cPanel Nutcase

  10. #10
    cPanel Partner NOC This forum account has been confirmed by cPanel staff to represent a vendor.cPanel Partner NOC Badge
    Join Date
    Nov 2001
    Location
    San Clemente, Ca
    Posts
    703

    Default

    i messed with the apache exploit alittle bit. That link that nick gave us a while back had source with it. Supposivly it would only work on openBSD but i noticed when i ran it on a RH7.1 machine running apache 1.3.20 (stupid POS plesk server) that it caused the child apache process's to sig11. I ran this exploit in a while true loop also just to see if i could totally kill apache and wasnt able too. Of course this was only a openbsd exploit but it does show that their is a flaw in the code.

    cpanel's rpmup i beleive will automatically upgrade openssh, as long as you guys didnt disable updates on your server that is
    Shaun Reitan
    NDCHost.com - cPlicensing.net - ProVPS.com
    Contact us for your cPanel Licensing needs! We Price Match, We provide Support, We take care of our customers!

  11. #11
    Member
    Join Date
    Mar 2002
    Posts
    67

    Default

    How to know if I am at the safe side or not ? (i.e. how to check out the ver. #'s)

    I just enabled the automatic security update function after reading this, but how can I know it kicked off ?

Similar Threads & Tags
Similar threads

  1. How do I open a port in ssh?
    By grabyourhosting in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 04-10-2007, 07:23 AM
  2. Open reseller account with ssh
    By jsilvestre in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 11-16-2006, 03:30 PM
  3. Upgrade Open SSh
    By haynesdavis in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 04-03-2006, 10:43 PM
  4. New WHM (SSH) exploit
    By WeMasterz5 in forum cPanel and WHM Discussions
    Replies: 8
    Last Post: 02-21-2005, 04:27 AM
  5. SSH exploit
    By sparek-3 in forum cPanel and WHM Discussions
    Replies: 19
    Last Post: 10-06-2003, 07:37 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube