Re: chkrootkit reporting sshd vulnerable?

From: Doctor Zen (hidden@from.spammers.net)
Date: 12/29/01


From: Doctor Zen <hidden@from.spammers.net>
Date: Sat, 29 Dec 2001 18:19:03 +0000

Richard E. Silverman wrote:

>>>>>> "DZ" == Doctor Zen <hidden@from.spammers.net> writes:
>
> DZ> ssh 3.0.1 (commercial) and chkrootkit v0.33 When I run chkrootkit
> DZ> locally it reports sshd not vulnerable, but when I ssh into the
> DZ> box and then run chkrootkit on it in the shell I get "sshd
> DZ> vulnerable but disabled".
> >> This is a little confusing. When you say "locally," I think you
> >> actually mean remotely -- that is on "the box" in question from
> >> elsewhere, examining its open network ports.
>
> DZ> No, "locally" means sitting at the keyboard with the box in front
> DZ> of me.
>
> Oh -- you meant you get different results depending on whether you log in
> on the console, versus logging via SSH and running the same tool? I would
> say in both cases you're running chkrootkit "locally." Whatever.

For example:

<sit in front of machineA>
root@machineA # chkrootkit
sshd not vulnerable

<go upstairs and sit in front of machineB>

me@machineB # ssh -l root machineA
root@machineA # chkrootkit
sshd vulnerable but disabled

I hope this clarifies it for you, and BTW if you reverse the scenario (test
machineB both locally and from machineA) the result is the same.

Doc



Relevant Pages

  • Re: chkrootkit reporting sshd vulnerable?
    ... >> DZ> locally it reports sshd not vulnerable, but when I ssh into the ... >> on the console, versus logging via SSH and running the same tool? ... > <sit in front of machineA> ...
    (comp.security.ssh)
  • chkrootkit reporting sshd vulnerable?
    ... When I run chkrootkit locally it reports sshd not vulnerable, ... ssh into the box and then run chkrootkit on it in the shell I get "sshd ... I was just a little worried about this, I ran chkrootkit in expert mode (ha ...
    (comp.security.ssh)
  • Re: chkrootkit reporting sshd vulnerable?
    ... >When I run chkrootkit locally it reports sshd not vulnerable, ... One of those patterns, being a pre-compiled password in a trojan sshd2 version, ...
    (comp.security.ssh)