Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - SSH root exploit in the wild - Patches available.

 
Thread Tools Search this Thread
Old 09-16-2003, 05:09 PM   #1
Default SSH root exploit in the wild - Patches available.




--
Get your Geek Goodies!
http://shop.security-forums.com

..: http://www.security-forums.com :.

Share your knowledge
It's a way to achieve
Immortality.




Lord Shaolin
  Reply With Quote
Old 09-16-2003, 05:11 PM   #2
Lord Shaolin
 
Posts: n/a
Default Re: SSH root exploit in the wild - Patches available.
Lord Shaolin <abuse@127.0.0.1> randomly produced:

Aww **** I went and his send again by mistake.

Anyway..

Full info here: http://www.security-forums.com/forum...pic.php?t=8380

CVS Diff patch:
http://www.freebsd.org/cgi/cvsweb.cg...r2=1.1.1.7&f=h

Mitigation from Full Disclosure:
http://lists.netsys.com/pipermail/fu...er/010116.html

Patch for OpenBSD:
ftp://ftp.openbsd.org/pub/OpenBSD/Op...sd3x_3.7.patch

Slashdot thread:
http://slashdot.org/articles/03/09/1...id=126&tid=172

Fix for the SSH in woody (stable) is available now from security.debian.org
which should be in your sources.list

apt-get update && apt-get upgrade

SID fix at http://incoming.debian.org/

Good luck!

ST

--
Get your Geek Goodies!
http://shop.security-forums.com

..: http://www.security-forums.com :.

Share your knowledge
It's a way to achieve
Immortality.




Lord Shaolin
  Reply With Quote
Old 09-17-2003, 03:59 AM   #3
jayjwa
 
Posts: n/a
Default Re: SSH root exploit in the wild - Patches available.
Lord Shaolin wrote:
> Lord Shaolin <abuse@127.0.0.1> randomly produced:
>
> Aww **** I went and his send again by mistake.
>
> Anyway..
>
> Full info here: http://www.security-forums.com/forum...pic.php?t=8380
>
> CVS Diff patch:
> http://www.freebsd.org/cgi/cvsweb.cg...r2=1.1.1.7&f=h
>
> Mitigation from Full Disclosure:
> http://lists.netsys.com/pipermail/fu...er/010116.html
>
> Patch for OpenBSD:
> ftp://ftp.openbsd.org/pub/OpenBSD/Op...sd3x_3.7.patch
>
> Slashdot thread:
> http://slashdot.org/articles/03/09/1...id=126&tid=172
>
> Fix for the SSH in woody (stable) is available now from security.debian.org
> which should be in your sources.list
>
> apt-get update && apt-get upgrade
>
> SID fix at http://incoming.debian.org/
>
> Good luck!
>
> ST
>


.....just got the Slackware Upgrade, it's a good thing I read this today.
People can't stop monkey'ing around with my FTP server, I'd hate to see
if those same people knew about this (although anyone who attempts to
bruteforce an anon server ain't too brite to begin with). Just try to
get on ANY of the upgrade sites! I had a nice long wait, it seems
everyone is thinking the same thing: patch it quick, buffer-troubles are
all the rage this year. When I finally was able to get on, I was #95 out
of a #96 slot machine, so that gives you an idea right there. Anyway, I
got the Slackware 9.0 upgrade and all is well.

--
-------------------------nonoffensive sig.v1.0RC1----------------------
>> jayjwa >> Reg.Linux user #207147


PGPKey: http://atr2.ath.cx/jayjwa.asc
Maildrop:jayjwa AT hotmail.com -- 4 Spammers:
mailto:



jayjwa
  Reply With Quote
Old 09-17-2003, 01:28 PM   #4
Lyle H. Gray
 
Posts: n/a
Default Re: SSH root exploit in the wild - Patches available.
jayjwa <> wrote in
news::

> ....just got the Slackware Upgrade, it's a good thing I read this
> today. People can't stop monkey'ing around with my FTP server, I'd
> hate to see if those same people knew about this (although anyone who
> attempts to bruteforce an anon server ain't too brite to begin with).
> Just try to get on ANY of the upgrade sites! I had a nice long wait,
> it seems everyone is thinking the same thing: patch it quick,
> buffer-troubles are all the rage this year. When I finally was able to
> get on, I was #95 out of a #96 slot machine, so that gives you an idea
> right there. Anyway, I got the Slackware 9.0 upgrade and all is well.


I just picked up the Redhat upgrade, after trying for 4 hours to get on the
network (I have a demo account, so a lower priority).



Lyle H. Gray
  Reply With Quote
Old 09-17-2003, 11:12 PM   #5
Dan Ferris
 
Posts: n/a
Default Re: SSH root exploit in the wild - Patches available.
Where is the link to the exploit code?

Lord Shaolin wrote:



Dan Ferris
  Reply With Quote
Old 09-19-2003, 04:23 AM   #6
joe
 
Posts: n/a
Default Re: SSH root exploit in the wild - Patches available.
Anyone got a copy of the sploit?

Giantkiller447

Dan Ferris wrote:

> Where is the link to the exploit code?
>
> Lord Shaolin wrote:




joe
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
New releases: Jane Austen Book Club,Across The Universe & Into The Wild: Updated complete R1 DVD Db & info lists Doug MacLean DVD Video 0 11-27-2007 07:43 AM
DVD Verdict reviews: THE WILD, WILD WEST: THE COMPLETE FIRST SEASON and more! DVD Verdict DVD Video 0 06-14-2006 09:22 AM
The Wild Wild West fredman DVD Video 6 03-04-2006 04:21 PM
DVD Verdict reviews: PLANETES (VOLUME 1), DRAGON BALL Z: VEGETA SAGA 1: INTO THE WILD, and more! DVD Verdict DVD Video 0 07-14-2005 09:11 AM
looking for CH Wild Wild West discs... Darrel Christenson DVD Video 0 11-26-2004 10:23 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46