Re:

From: Greg Shenaut (greg@bogslab.ucdavis.edu)
Date: 10/11/01


To: security@FreeBSD.ORG
Date: Wed, 10 Oct 2001 15:40:27 -0700
From: Greg Shenaut <greg@bogslab.ucdavis.edu>

In message <007b01c151c0$646ab510$252da818@sioux>, "Jonathan M. Slivko" cleopede:

>First, cvsup to 4.4-STABLE. Then, you should be patched. 4.4-STABLE (and =
>-RELEASE) incorporate the patch needed to secure the machine. -- =

But turn off telnet until you install the patched version !

Greg Shenaut

>Jonathan
> ----- Original Message -----=20
> From: asssaf123 kachlon=20
> To: freebsd-questions@FreeBSD.ORG=20
> Sent: Wednesday, October 10, 2001 3:16 PM
>
>
> hello=20
> i have box with freebsd in it:
>
> # uname -r
> RELENG_4_2001_06_29_NOSRC
>
> i want to secure this box from telnetd remote exploit but with out to =
>close telnet
>
> what can i do ?
>
> the info in ur site is dont work
>
> please help me,
>
> assaf k
>
>
>
>
>
>-------------------------------------------------------------------------=
>-----
> Get your FREE download of MSN Explorer at http://explorer.msn.com
> To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe =
>freebsd-questions" in the body of the message=20
>
>------=_NextPart_000_0078_01C1519E.DC9576F0
>Content-Type: text/html;
> charset="iso-8859-1"
>Content-Transfer-Encoding: quoted-printable
>
><!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
><HTML><HEAD>
><META http-equiv=3DContent-Type content=3D"text/html; =
>charset=3Diso-8859-1">
><META content=3D"MSHTML 6.00.2600.0" name=3DGENERATOR>
><STYLE></STYLE>
></HEAD>
><BODY bgColor=3D#ffffff>
><DIV><FONT face=3DArial size=3D2>First, cvsup to 4.4-STABLE. Then, you =
>should be=20
>patched. 4.4-STABLE (and -RELEASE) incorporate the patch needed to =
>secure the=20
>machine. -- Jonathan</FONT></DIV>
><BLOCKQUOTE=20
>style=3D"PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; =
>BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
> <DIV style=3D"FONT: 10pt arial">----- Original Message ----- </DIV>
> <DIV=20
> style=3D"BACKGROUND: #e4e4e4; FONT: 10pt arial; font-color: =
>black"><B>From:</B>=20
> <A title=3Dasssaf123@hotmail.com =
>href=3D"mailto:asssaf123@hotmail.com">asssaf123=20
> kachlon</A> </DIV>
> <DIV style=3D"FONT: 10pt arial"><B>To:</B> <A=20
> title=3Dfreebsd-questions@FreeBSD.ORG=20
> =
>href=3D"mailto:freebsd-questions@FreeBSD.ORG">freebsd-questions@FreeBSD.O=
>RG</A>=20
> </DIV>
> <DIV style=3D"FONT: 10pt arial"><B>Sent:</B> Wednesday, October 10, =
>2001 3:16=20
> PM</DIV>
> <DIV><BR></DIV>
> <DIV>
> <DIV>hello </DIV>
> <P>i have box with freebsd in it:</P>
> <P># uname -r<BR>RELENG_4_2001_06_29_NOSRC</P>
> <P>i want to secure this box from telnetd remote exploit&nbsp;but with =
>out to=20
> close telnet</P>
> <P>what can i do ?</P>
> <P>the info in ur site is dont work</P>
> <P>please help me,</P>
> <P>assaf k</P>
> <P>&nbsp;</P></DIV><BR clear=3Dall>
> <HR>
> Get your FREE download of MSN Explorer at <A=20
> href=3D"http://explorer.msn.com">http://explorer.msn.com><BR>To =
>Unsubscribe:=20
> send mail to
majordomo@FreeBSD.org with "unsubscribe =
>freebsd-questions" in the=20
> body of the message </BLOCKQUOTE></BODY></HTML>
>
>------=_NextPart_000_0078_01C1519E.DC9576F0--
>
>
>To Unsubscribe: send mail to majordomo@FreeBSD.org
>with "unsubscribe freebsd-security" in the body of the message

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: HELP: how to enable telnet?
    ... >> Just some questions about telnet. ... I just installed FreeBSD. ... Then how can I get SSH working? ... later I want to use Windows XP/2K3. ...
    (freebsd-newbies)
  • [Full-disclosure] FreeBSD zeroday
    ... And possible remote root code excution. ... There is a rather big bug in the current FreeBSD telnetd daemon. ... The telnet protocol allows to pass environment variables inside the ...
    (Full-Disclosure)
  • FreeBSD Security Advisory FreeBSD-SA-01:25.kerberosIV
    ... Corrected: 2000-12-13 (FreeBSD 4.2-STABLE) ... FreeBSD includes the KTH Kerberos ... filtering of environmental variables by the KerberosIV-adapted telnet ... This vulnerability exists in the kdc_reply_ciphercall. ...
    (FreeBSD-Security)
  • telnet and rlogin problems
    ... 2nd Ed Absolute FreeBSD and in both the NOTES ... able to either telnet or rlogin to the box. ... config file when going to 6.2 - I believe that I am ...
    (freebsd-questions)
  • Re: FreeBSD Security Advisory FreeBSD-SA-05:01.telnet
    ... In general it's fine to bug the security team directly of stuff like ... the security advisories just have you rebuild the ... Due to multiple telnet versions (especially in FreeBSD 4) it was ...
    (FreeBSD-Security)

Quantcast