Re: hacked through ssh

From: Darren Tucker (dtucker_at_dodgy.net.au)
Date: 03/10/04


Date: Wed, 10 Mar 2004 05:39:02 +0000 (UTC)

In article <704ecc39.0403091430.644561b5@posting.google.com>,
John <mcgowan@lynch2.com> wrote:
>I've got a D2D backup applicance that came preinstalled with a version
>of RH Linux. Not sure which version. However I am sure that it is
>running OpenSSH_3.1p1.
[...]
>I'm 99% convinced (from searching google for half a day) that this was
>due to the old version of OpenSSH and the fact that I had SSH open up
>to the outside world. But I have not encountered any real proof that
>what I'm looking at came from those mistakes.

That version of OpenSSH did have an exploitable problem in some
configurations (unless it was patched by the vendor):
http://www.openssh.com/txt/preauth.adv

-- 
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.


Relevant Pages

  • End of my rope
    ... I'm running Linux with OpenSSH and Windows with Putty. ... negotiation with an to an outside OpenSSH server on Linux. ... OpenSSH client on Linux outside my network hangs immediatly after ...
    (SSH)
  • Re: Somebody is keep trying to ssh into my systems, how can I stop that?
    ... That means that you can NOT take what is true about OpenBSD ... to Linux because, as you point out here, Linux IS NOT BSD. ... OpenSSH is part of OpenBSD, but it also runs on Linux. ... anything with massive amounts of unrelated data the way you do. ...
    (comp.os.linux.security)
  • Re: tcsetpgrp()
    ... Which SSH implementation and version thereof are you running? ... On QNX the pty allocation process apparently ... In the next release of OpenSSH, ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • Re: windows update question
    ... >>> Good judgement comes from experience. ... >> hey steve, ... > Find a couple of gig free on your drive and install Linux on it. ... i've spent most of this afternoon researching windows security,(or lack ...
    (alt.computer.security)
  • Re: how to find out the version of a running sshd
    ... >> I have openssh sshd running on my linux 7.2. ... Just install the RedHat 7.2 updated RPM. ...
    (comp.security.ssh)

Quantcast