Welcome, Guest. Please login or register.
July 22, 2025, 09:02:43 PM

Login with username, password and session length

Search:     Advanced search
we're back, baby
*
Home Help Search Login Register
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: SECURITY: Damn you OpenSSH! (GSSAPI remote code execution vulnerability) 0 Members and 1 Guest are viewing this topic.
Pages: [1] Go Down Print
Author Topic: SECURITY: Damn you OpenSSH! (GSSAPI remote code execution vulnerability)  (Read 2030 times)
bhodi
Moderator
Posts: 6817

No lie.


on: April 04, 2007, 10:53:56 AM

You're supposed to be secure! Why you gotta make me hit you?

That's an awesome list of vulnerable systems. This is pretty big, though they claim "chance of a successful exploit of this nature is considered minimal" -- keep in mind, you've got to be running GSSAPI enabled.. like with kerberos or something. Like I do. Let's see... how many thousands of servers do we have to patch? Goody.

http://www.securityfocus.com/bid/20241
« Last Edit: April 06, 2007, 06:37:06 PM by Trippy »
Yegolev
Moderator
Posts: 24440

2/10 WOULD NOT INGEST


WWW
Reply #1 on: April 04, 2007, 10:57:48 AM

Meh.  I will get irritated by this after we close down ftp and rexec.

Why am I homeless?  Why do all you motherfuckers need homes is the real question.
They called it The Prayer, its answer was law
Mommy come back 'cause the water's all gone
Trippy
Administrator
Posts: 23657


Reply #2 on: April 04, 2007, 05:37:15 PM

OpenSSH has had its share of security holes over the years. I'm pretty sure the one time one of my Linux boxes got hacked was through a vulnerable version of OpenSSH. Fortunately for me my version of Linux was so decrepit that the l33t haxx0r code they downloaded onto my machine wouldn't even run properly.
Samwise
Moderator
Posts: 19324

sentient yeast infection


WWW
Reply #3 on: April 04, 2007, 07:40:24 PM

Security through obscurity ftw.
Lantyssa
Terracotta Army
Posts: 20848


Reply #4 on: April 04, 2007, 08:36:30 PM

I used to admin a VMS machine configured by someone so paranoid it had no "standard" paths.  It was a bloody pain, but we were pretty certain even if someone got in they would be incapable of doing anything.  We certainly weren't...

If only it hadn't been our mail server. cry

Hahahaha!  I'm really good at this!
bhodi
Moderator
Posts: 6817

No lie.


Reply #5 on: April 10, 2007, 09:35:02 PM

This can probably be unstickied.. it's fairly rare and probably doesn't affect many people who read this :) I was just really annoyed when I saw it.
« Last Edit: April 10, 2007, 09:46:58 PM by bhodi »
Pages: [1] Go Up Print 
f13.net  |  f13.net General Forums  |  General Discussion  |  Topic: SECURITY: Damn you OpenSSH! (GSSAPI remote code execution vulnerability)  
Jump to:  

Powered by SMF 1.1.10 | SMF © 2006-2009, Simple Machines LLC