New SSH exploit found in wild! Admins beware!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • com
    Confirmed User
    • Aug 2003
    • 4541

    #1

    New SSH exploit found in wild! Admins beware!

    The attack makes an enormous amount of ssh connections and attempts various offsets until it finds one that works permitting root login.

    I have received numerous messages from folks requesting anonymity or direct-off-list-reply confirming this exploit;

    http://lists.netsys.com/pipermail/fu...ead.html#10103

    Real. Professional. Hosting.
    .:Expect Nothing Less:.
    320-078-843 :: www.realprohosting.com :: [email protected]
  • sweet7
    Confirmed User
    • May 2003
    • 1792

    #2
    broken link
    ICQ: 282814268

    Comment

    • NetRodent
      Confirmed User
      • Jan 2002
      • 3985

      #3
      http://www.netsys.com/cgi-bin/displaynews?a=652
      "Every normal man must be tempted, at times, to spit on his hands, hoist the black flag, and begin slitting throats."
      --H.L. Mencken

      Comment

      • skazzel
        Confirmed User
        • Jun 2002
        • 270

        #4
        I am going to bump this...this is a remote root exploit with no patch available at the moment. Probably 90% of us here run our sites on servers with SSH installed.

        You should firewall off the ssh port so it is only available from ip addresses that you will need to access it from.
        FTVGirls simply convert better.
        More free content than SobeGirl and
        conversions almost as good as Swoit!

        Comment

        • NetRodent
          Confirmed User
          • Jan 2002
          • 3985

          #5
          There is a patch for it now, and OpenSSH 3.7 (came out today) does not have this vulnerablity. Not all of the OpenSSH mirrors have updated yet though.
          "Every normal man must be tempted, at times, to spit on his hands, hoist the black flag, and begin slitting throats."
          --H.L. Mencken

          Comment

          • extreme
            Confirmed User
            • Oct 2002
            • 2120

            #6
            Red Hat linux patches are out ...

            Comment

            • rossiya2
              Confirmed User
              • Nov 2002
              • 287

              #7
              I don't use openssh DOH

              It's like the 20th exploit for that program.

              For the same 'hosting companies' that run named as superuser I guess.....
              <a href="mailto:[email protected]">sales@cologroup. com</a> | 52027820 | <a href="http://www.cologroup.com">www.cologroup.com</a>

              Comment

              • ytcracker
                stc is the greatest
                • Dec 2002
                • 12403

                #8
                good looking out bump

                ive been patching shit all morning
                www.ytcracker.com | www.digitalgangster.com
                i love you

                Comment

                • JDog
                  Confirmed User
                  • Feb 2003
                  • 7453

                  #9
                  Hmm, our host is already on this and upgrading.

                  jDOG
                  NSCash now powering ReelProfits.com
                  ALSO FEATURING: NSCash.com :: SoloDollars.com :: ReelProfits.com :: BiminiBucks.com :: VOD
                  PROGRAMS COMING SOON: Greedy Bucks :: Vengeance Cash
                  NOW OFFERING OVER 60 SITES
                  CONTACT :: JAMES SMITH :: CHIEF TECHNOLOGY OFFICER :: ICQ (711385133)

                  Comment

                  • rossiya2
                    Confirmed User
                    • Nov 2002
                    • 287

                    #10
                    Why do you guys patch when you should delete? Herd mentality?
                    <a href="mailto:[email protected]">sales@cologroup. com</a> | 52027820 | <a href="http://www.cologroup.com">www.cologroup.com</a>

                    Comment

                    Working...