login
Header Space

 
 

dragonflybsd-user mailing list

FromSubjectsort iconDate
Matthew Dillon
LIST OF COMPROMISED SSH KEYS ON LEAF
The following accounts on LEAF had compromised keys: hasso Hasso Tepper mayurb Mayur Bhosle thacker Nirmal Thacker I have disabled the keys in question and I am CCing this to the account holders as well. Please generate new keys and and email me I manually checked all the authorized_keys files and none of them had any options, so I think the scanner found them all. -Matt Matthew Dillon <dillon@backplane.com>
May 16, 12:59 pm 2008
Matthew Dillon
Re: HEADS UP: blacklisting of weak ssh keys
I am downloading the key fingerprings debian published and will run it against all the accounts on leaf, pkgbox, and other machines. -Matt Matthew Dillon <dillon@backplane.com>
May 16, 12:39 pm 2008
Aggelos Economopoulos
Re: HEADS UP: blacklisting of weak ssh keys
On Friday 16 May 2008, Matthew Dillon wrote: This just in: if you were going to use ssh-vulnkey, debian just announced they have been told about (and addressed) another shortcoming of the tool: http://lists.debian.org/debian-security-announce/2008/msg00155.html Aggelos
May 16, 12:46 pm 2008
Aggelos Economopoulos
HEADS UP: blacklisting of weak ssh keys
By now every administrator and/or ssh user should have heard about the bug in debian's ssl library. If you've been offline for the past few days, start here: http://lists.debian.org/debian-security-announce/2008/msg00152.html http://metasploit.com/users/hdm/tools/debian-openssl While our OpenSSL library does not suffer from this bug, it possible that some of your users have generated their keys on a buggy debian or debian-derivative (e.g. Ubuntu) system. This would mean their account can be ea...
May 16, 11:40 am 2008
previous daytodaynext day
May 14, 2008May 16, 2008May 17, 2008
speck-geostationary