Re: CERT Advisory CA-2002-24 Trojan Horse OpenSSH Distribution (fwd)

From: Rob Andrews (rob@cyberpunkz.org)
Date: 08/02/02


Date: Thu, 1 Aug 2002 23:11:53 -0400
From: Rob Andrews <rob@cyberpunkz.org>
To: freebsd-security@FreeBSD.ORG



.- - - - - - Dag-Erling Smorgrav wrote (2002/08/01 at 09:02:48 PM) - - - - - -
|
|> Chris Miller <ctodd@netgate.net> writes:
|> > Are we affected by this? I couldn't find bf-test.c in the openssh
|> > directory in /usr/ports. I'm assuming that since the part of the automagic
|> > process of building the port involves checking the checksum that we are
|> > safe, but I thought it best to ask.
|>
|> We're safe.
|>

Technically, yes provided system maintainers did not install openssh during
the time period the trojaned tarballs were available and didn't decide to
force the software to install on the system when the md5 checksum failed
to match.

During the period openssh was trojaned I was doing system upgrades and
rebuilding openssh as well with updated libraries. As a rule I never force
software to install if the md5 checksum fails.. Some people ignore this
and install anyway.

--
Rob Andrews
RELI Networks, Inc.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: trojaned SSHD ?
    ... I'd recommend moving to OpenSSH, which supports both ssh1 and ssh2 ... platforms, including Solaris. ... Information relevant to the installation of SSH on NCMIR systems. ... * Install Zlib 1.1.2 libraries, compiling from source, on Solaris and IRIX ...
    (Focus-SUN)
  • Re: Authentication failed suddenly
    ... I had to play the gcc re-installation game to get OpenSSH 3.4p1 to ... this is absolutely no reason to tell people to stay away from ... On both the Solaris installs I did, I built with the default privsep ... actually the 'make install' did the latter for me) - ...
    (comp.security.ssh)
  • RE: OpenSSH b0rked (was RE: Problems with IPFW patch)
    ... fix was the config file. ... No reboots or restarting sshd necessary. ... > Subject: RE: OpenSSH b0rked ... >> annoying install sequence - you can't define where it gets ...
    (FreeBSD-Security)
  • Re: OpenSSL/0.9.7c-p1 & OpenSSH_3.5p1
    ... which means that all known bugs in OpenSSL and OpenSSH will have been ... If you install from ports, there is a facility for you to install the ... port in such a way as to overwrite the equivalents in the base system. ... Otherwise, if you choose to upgrade to a different source branch, you ...
    (freebsd-questions)
  • Fw: Re: OpenSSL/0.9.7c-p1 & OpenSSH_3.5p1
    ... which means that all known bugs in OpenSSL and OpenSSH will have been ... If you install from ports, there is a facility for you to install the ... port in such a way as to overwrite the equivalents in the base system. ... Otherwise, if you choose to upgrade to a different source branch, you ...
    (freebsd-questions)

Loading