ATTN: All Unix Dedicated Server Owners (Major security flaw)

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Dreamman010
    Confirmed User
    • Jan 2002
    • 1081

    #1

    ATTN: All Unix Dedicated Server Owners (Major security flaw)

    Hello,

    A new exploit for OpenSSH has just been released on BUGTRAQ (security message board) that affects OpenSSH (the daemon that you use for remote administration). Versions affected by the exploit are: OpenSSH 2.9.9 - 3.3
    The easiest way to check which version you are running is to open telnet and connect to port 22 on your server. It will tell you the version. If you do not upgrade your system, it can be compromised sooner or later and get trojaned.

    More information on the exploit/vulnerability can be found here:

    http://www.cert.org/advisories/CA-2002-18.html


    Lastly, about a week ago, there was another exploit released for Apache 1.3.24 and below. I really suggest you to upgrade to 1.3.26 because a worm that is operating in the wild has already been released and you could be the next victim. More information about the Apache flaw can be found here: http://www.cert.org/advisories/CA-2002-17.html

    So in general, if you don't want to get compromised, upgrade to Apache 1.3.26 and OpenSSH 3.4 immediately.

    Feel free to contact me via ICQ 11611813 if you have any questions.

    -Dreamman
    Last edited by Dreamman010; 07-01-2002, 11:02 AM.
    <a href="http://www2.famoushost.com/home.php" target="_blank"><b><FONT COLOR="FFFF00">www.FamousHost.com</font></b></a><br>Free Hosting With No Headers, Real FTP, <u>Get listed on the biggest TGP's with us!</u>
  • Petr
    Confirmed User
    • Mar 2002
    • 502

    #2
    (Actually, the news about openssh bug is about one week old...)

    Comment

    • Nysus
      Confirmed User
      • Aug 2001
      • 7817

      #3
      Yeah - It's a bit old.

      Cheers,
      Matt
      What name is pr0 / Untouched Markets using these days? Untouched Markets - pr0 - Refund My Money Now

      Someone owes me $2,000 because they didn't do any work that was paid for *pointing at pr0 / William / UntouchedMarkets*

      See http://www.gfy.com/showthread.php?p=16744521 and for more detailed see http://www.gfy.com/showthread.php?t=948645

      Comment

      Working...