FW: OpenSSH anomaly

From: AJ Cochenour (ajc_at_ipervasive.com)
Date: 02/23/04

  • Next message: Will Tipton: "Re: OpenSSH anomaly"
    To: <incidents@securityfocus.com>
    Date: Sun, 22 Feb 2004 21:42:35 -0700
    
    

    No input on cause, however *if* it exhibits these symptoms again run the
    following from the console:

    ps -auxwwf | grep ssh (to get PID)
    strace -p <PID>

    Then attempt another ssh session, strace should give a complete (if
    exhausting) accounting of events.

    aj

    -----Original Message-----
    From: Mike Hoskins [mailto:mike@adept.org]
    Sent: Sunday, February 22, 2004 3:36 PM
    To: incidents@securityfocus.com
    Subject: Re: OpenSSH anomaly

    On Sun, 22 Feb 2004, Benjamin Franz wrote:
    > I'm running a RedHat Enterprise 3 ES server that has been running
    fairly
    > reliably for a month. This morning we could not remotely login to the
    > server via SSH because openssh would terminate the connection
    immediately
    > (no delay) after apparently successfully logging in - without giving a
    > prompt.

    did you by chance attempt doing an `ssh -v ...` to the host while it was
    exhibiting this behavior? the verbose debug output would at least let
    you
    see precisely what was happening wrt SSH when the disconnect occured.

    -m

    ------------------------------------------------------------------------

    ---
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.
    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.
    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_incidents_040219
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Free trial: Astaro Security Linux -- firewall with Spam/Virus Protection
    Protect your network with the comprehensive security solution that
    integrates six applications for ease of use and lower TCO.
    Firewall - Virus protection - Spam protection - URL blocking - VPN
    - Wireless security.
    Download 30-day evaluation at:
    http://www.securityfocus.com/sponsor/Astaro_incidents_040219
    ----------------------------------------------------------------------------
    

  • Next message: Will Tipton: "Re: OpenSSH anomaly"

    Relevant Pages

    • RE: SSH Setup
      ... I wouldn't say that this was related to SSHD at all. ... Subject: SSH Setup ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
      (Security-Basics)
    • Securing FileZilla FTP Server with Zebedee Secure IP Tunnel
      ... I spent some time yesterday and put together a tutorial on getting FileZilla Server working with Zebedee Secure IP Tunnel, which is similar to SSH in function. ... Astaro Security Linux -- firewall with Spam/Virus Protection ...
      (Security-Basics)
    • Re: [Full-disclosure] Why Vulnerability Databases cant do everything
      ... best to relegate programming to a ... is a big difference between these two views of information security. ... but not nearly as important as designing secure systems. ... My favorite example to illustrate this point - ssh. ...
      (Bugtraq)
    • RE: Linux hacked
      ... Also, what exactly did the history file show, can you paste it into a mail ... > First let me say I'm a security novice. ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
      (Security-Basics)
    • Re: Secure Way of Remotely Viewing a Desktop...
      ... Remote Administrator (aka RAdmin) from Famatech. ... With respect to security, Famatech claims all data ... VNC tunneled through SSH ...
      (Security-Basics)