-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On Thursday, 15.05.2008 at 07:11 +0200, Otto Moerbeek wrote:For info Debian (and thus also Ubuntu) have released updated openssh packages which include a new tool called ssh-vulnkey which can be used to check the running system[1] for vulnerable keys: ssh-vulnkey works similarly to the Perl script in the Debian announcement. The package has also had an additional option added to sshd_config which blacklists (i.e. stops use of) these vulnerable keys. Once updated, Debian and Ubuntu systems will reject connections based on these vulnerable keys. One of my machines at home is an Ubuntu laptop and my OpenBSD box had a copy of its public key in ~/.ssh/authorized_keys so that logging into it is simpler from the laptop - if this box were exposed to the world, then it would only take 32,000 attempts to get into it, if my username is known. I've removed the vulnerable public key from the OpenBSD box now. I believe the original assessment was correct: *all* systems running SSH ought to check for these vulnerable keys, not just those systems running Debian or derivatives. Yes, it's Debian's "fault", but we all have to manage the consequences. If only Debian and Ubuntu's openssh is updated, then they will be *more* secure than non-updated OpenBSD, Solaris, Red Hat Linux etc. Cheers, Dave. [1] It checks host keys and also the contents of authorized_keys - -- Dave Ewart iD8DBQFIK/wbbpQs/WlN43ARAnKvAJ4pYbbhW4pCYvp7hqApTCqr43BWmwCg864Q xBTY5bfIl4KLiSsYsDMplS8= =5mhX -----END PGP SIGNATURE-----
| Dave Young | Re: 2.6.24-rc3-mm1 |
| Linus Torvalds | Linux 2.6.27-rc8 |
| monstr | [PATCH 52/56] microblaze_v2: pci headers |
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
git: | |
| Steffen Prohaska | Re: CRLF problems with Git on Win32 |
| Junio C Hamano | Re: [kernel.org users] [RFD] On deprecating "git-foo" for builtins |
| Junio C Hamano | Re: Cleaning up git user-interface warts |
| Jakub Narebski | Re: VCS comparison table |
| Larry McVoy | Re: tcp bw in 2.6 |
| Gerrit Renker | Re: [DCCP] [RFC] [Patchv2 1/1]: Queuing policies -- reworked version of Tomasz's p... |
| Jussi Kivilinna | [PATCH v2 3/3] net_sched: Add size table for qdiscs |
| Gerrit Renker | [PATCH 13/37] dccp: Deprecate Ack Ratio sysctl |
| Richard Stallman | Real men don't attack straw men |
| Tanvir | Re: Adobe Flash on OpenBSD |
| Zbigniew Baniewski | Re: What is our ultimate goal?? |
| Kevin Neff | Patching a SSH 'Weakness' |
| high memory | 9 hours ago | Linux kernel |
| semaphore access speed | 12 hours ago | Applications and Utilities |
| the kernel how to power off the machine | 13 hours ago | Linux kernel |
| Easter Eggs in windows XP | 15 hours ago | Windows |
| Shared swap partition | 16 hours ago | Linux general |
| Root password | 16 hours ago | Linux general |
| Where/when DNOTIFY is used? | 18 hours ago | Linux kernel |
| How to convert Linux Kernel built-in module into a loadable module | 21 hours ago | Linux kernel |
| Linux 2.6.24 and I/O schedulers | 21 hours ago | Linux kernel |
| USB Driver -- Interrupt Polling -- A Little Help Please | 1 day ago | Linux general |
