| From | Subject | Date |
|---|---|---|
| Matthew Dillon | LIST OF COMPROMISED SSH KEYS ON LEAF
The following accounts on LEAF had compromised keys:
hasso Hasso Tepper
mayurb Mayur Bhosle
thacker Nirmal Thacker
I have disabled the keys in question and I am CCing this to the
account holders as well. Please generate new keys and and email me
I manually checked all the authorized_keys files and none of them had
any options, so I think the scanner found them all.
-Matt
Matthew Dillon
<dillon@backplane.com>
| May 16, 12:59 pm 2008 |
| Matthew Dillon | Re: HEADS UP: blacklisting of weak ssh keys
I am downloading the key fingerprings debian published and will run it
against all the accounts on leaf, pkgbox, and other machines.
-Matt
Matthew Dillon
<dillon@backplane.com>
| May 16, 12:39 pm 2008 |
| Aggelos Economopoulos | Re: HEADS UP: blacklisting of weak ssh keys
On Friday 16 May 2008, Matthew Dillon wrote:
This just in: if you were going to use ssh-vulnkey, debian just announced they
have been told about (and addressed) another shortcoming of the tool:
http://lists.debian.org/debian-security-announce/2008/msg00155.html
Aggelos
| May 16, 12:46 pm 2008 |
| Aggelos Economopoulos | HEADS UP: blacklisting of weak ssh keys
By now every administrator and/or ssh user should have heard about the
bug in debian's ssl library. If you've been offline for the past few days,
start here:
http://lists.debian.org/debian-security-announce/2008/msg00152.html
http://metasploit.com/users/hdm/tools/debian-openssl
While our OpenSSL library does not suffer from this bug, it possible that
some of your users have generated their keys on a buggy debian or
debian-derivative (e.g. Ubuntu) system. This would mean their account can be
ea...
| May 16, 11:40 am 2008 |
| previous day | today | next day |
|---|---|---|
| May 14, 2008 | May 16, 2008 | May 17, 2008 |
| Pardo | Re: pthread_create() slow for many threads; also time to revisit 64b context switc... |
| Andrew Morton | 2.6.23-rc4-mm1 |
| Albert Cahalan | JIT emulator needs |
| Jack Stone | [PATCH 5/7] Replace DPRINTK with pr_debug in ncpfs |
git: | |
| Theodore Tso | Re: git on MacOSX and files with decomposed utf-8 file names |
| Johan Herland | [PATCH 0/6] Refactor the tag object |
| Ingo Molnar | [OT] Your branch is ahead of the tracked remote branch 'origin/master' by 50 commi... |
| Johannes Schindelin | [WIP PATCH] Add 'git fast-export', the sister of 'git fast-import' |
| Mark Reitblatt | US Export of Cryptography |
| Rico Secada | About non-free software in OpenBSD |
| Reza Muhammad | Dell PowerEdge 1950 III / R200 |
| Ivo Chutkin | problem installing some packages on 4.2 |
| David Miller | Re: [RFC PATCH 05/13] ip: support for TX timestamps on UDP and RAW sockets |
| Adrian Bunk | [2.6 patch] remove CONFIG_NET_SCH_RR |
| Erik Mouw | Lots of "BUG eth1 code -5 qlen 0" messages in 2.6.24 |
| David Miller | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
