Debian OpenSSH vulnerability
Posted in Debian, Linux on May 15, 2008 at 11:53 am
Any Debian user please note the recent security advisory, apply immediately, and then look at this link to find what you next need to do:
The vulnerability is in the crypto (openssl) library, causing keys generated on a Debian system to be emminantly predicatable. This site has generated keys, and fingerprints for all keys actually possible to be created using the bug. This means its HIGHLY likely in my opinion that a hackers or a worm may start using this soon. They also say they may be making an auto-exploit tool - The site linked above quotes “In the near future, this site will be updated to include a brute force tool that can be used quickly gain access to any SSH account that allows public key authentication using a vulnerable key”
Basically the problem exists if you allow identity/logins to be asserted via a certificate(authorized_keysfile). Ie, login with no password. You can guess the first port of attack will be on the root@your box - so if you allow remote root logins via certificate on debian, please be careful.
Pretty critical bug, but as always a great response from Debian and the community on this. Other Debian based distruibutions have not been confirmed vulnerable at this time (though may not be found to be if they did not merge the faulty code into their distributions). Update according to another blog : Any SSH or SSL keys generated on all Debian-derived systems corresponding to
Make a comment
Archives
- July 2009
- June 2009
- April 2009
- March 2009
- February 2009
- January 2009
- December 2008
- November 2008
- October 2008
- September 2008
- August 2008
- July 2008
- June 2008
- May 2008
- April 2008
- March 2008
- February 2008
- January 2008
- December 2007
- November 2007
- October 2007
- September 2007
- August 2007
- April 2007
- March 2007
- February 2007
- January 2007
- October 2006
- September 2006
- August 2006
Most commented posts
Highest Rated Blog Posts
- Debian & APT - Why I love it (100%)
- PicardTagger - most useful mp3 tool ever? (100%)
- Nokia Comes with Music - doomed to fail? (100%)
- The death of the British High Street (100%)
- Fighting Spam with Spamassassin (100%)
- iPhone 2.1 Upgrade - Genius! (100%)
- ADSL and why I am happy a neighbor is moving. (80%)
- Homebuilt NAS - one week on (80%)
- Second Life - a big waste of time? (75%)
- Day 4 of me.com/iPhone, my mini-review (73.4%)

