Debian OpenSSH vulnerability
Posted in Debian, Linux on May 15, 2008 at 11:53 am
Any Debian user please note the recent security advisory, apply immediately, and then look at this link to find what you next need to do:
The vulnerability is in the crypto (openssl) library, causing keys generated on a Debian system to be emminantly predicatable. This site has generated keys, and fingerprints for all keys actually possible to be created using the bug. This means its HIGHLY likely in my opinion that a hackers or a worm may start using this soon. They also say they may be making an auto-exploit tool - The site linked above quotes “In the near future, this site will be updated to include a brute force tool that can be used quickly gain access to any SSH account that allows public key authentication using a vulnerable key”
Basically the problem exists if you allow identity/logins to be asserted via a certificate(authorized_keysfile). Ie, login with no password. You can guess the first port of attack will be on the root@your box - so if you allow remote root logins via certificate on debian, please be careful.
Pretty critical bug, but as always a great response from Debian and the community on this. Other Debian based distruibutions have not been confirmed vulnerable at this time (though may not be found to be if they did not merge the faulty code into their distributions). Update according to another blog : Any SSH or SSL keys generated on all Debian-derived systems corresponding to “Debian Etch and later”: for Ubuntu, this means Feisty 7.04, Gutsy 7.10 and Hardy 8.04
Hope this helps someone getting hacked/a worm - the links above have more technical detail - just want to get the word out just HOW important this is if you use keys on Debian/Ubuntu.
Futher Update : Note on my personal machine I just spotted this update didn’t apply until I ran a dist-upgrade. A simple check that its on is to run ssh-vulnkey on your box as root. If the program exists on Debian the patch is applied already. If not, its not (as was introduced with patch).
Most commented posts
Highest Rated Blog Posts
- Debian & APT - Why I love it (100%)
- Nokia Comes with Music - doomed to fail? (100%)
- The death of the British High Street (100%)
- PicardTagger - most useful mp3 tool ever? (100%)
- Fighting Spam with Spamassassin (100%)
- iPhone 2.1 Upgrade - Genius! (100%)
- ADSL and why I am happy a neighbor is moving. (80%)
- Homebuilt NAS - one week on (80%)
- Day 4 of me.com/iPhone, my mini-review (73.4%)
- Eve Online - My new addiction (50%)

