Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Results 1 to 9 of 9

This is a discussion on Alleged 0day in OpenSSH in the Open Discussion & Chit-chat forum
Without wishing to fan the flames of rumour and hearsay, I was wondering whether Jag were considering locking down SSH access, as some other hosts ...

  1. #1
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582

    Alleged 0day in OpenSSH

    Without wishing to fan the flames of rumour and hearsay, I was wondering whether Jag were considering locking down SSH access, as some other hosts are, in response to the alleged 0day in OpenSSH? If so, will we get any warning?

    Before anyone panics, no one is sure whether this is anything more than a hoax, but at the very least HostGator claim to be patching something.

  2. #2
    the Windlord Gwaihir's Avatar
    Join Date
    Jun 2002
    Posts
    2,562
    It also says it doesn't affect the latest version, so for JagPC it's just a matter of making sure all servers run that. (Which, in particular for OpenSSH, I hope is standard practice anyway.)
    Regards,

    Wim Heemskerk
    ---
    Visit MeCCG.net - Cardgaming in J.R.R. Tolkien's Middle-earth
    And Gwaihir.net - The Middle-earth CCG store

  3. #3
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Depends on what you mean by latest version. RHEL and therefore CENTOS backport bug fixes.

    Quote Originally Posted by n3kton
    Actually, 4.3 *is* the latest RHEL/CentOS SSH version. openssh-server-4.3p2-29.el5 has been backported by RH engineers to supposedly patch all of the bugs that have since been disclosed up until the latest OpenSSH versions released by the OpenBSD project people. For enterprise stability purposes (which is why Gov and large businesses buy Red Hat) the versions and features are kept approximately the same as the original RHEL distribution release, but bugs are cleaned up. So if this vulnerability is valid, then possibilities include: 1. All OpenSSH versions are vulnerable 2. Unknown vulnerability was unwittingly patched as part of a version feature upgrade with newer-than-4.3 OpenSSH versions 3. Red Hat engineers failed to properly fix bugs with their backporting efforts.

  4. #4
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Just FUD then.

    Why on Earth did hosts start disabling SSH?

  5. #5
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,304
    Thanks for spreading it.
    Good luck

  6. #6
    Ron
    Ron is offline
    Loyal Client
    Join Date
    Aug 2002
    Posts
    7,304
    Actually, I really did enjoy reading up on it. Made me realize just how little I care about things like antisec.
    Good luck

  7. #7
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Quote Originally Posted by Ron
    Thanks for spreading it.
    Yeah, fools rush in, or something like that. Sorry.

    The main reason I gave it any credence was Host X taking SSH offline, claiming they had all sorts of secret intell. I won't be moving my business there any time soon.

    Quote Originally Posted by Ron
    Made me realize just how little I care about things like antisec.
    Agreed.

  8. #8
    Loyal Client the_ancient's Avatar
    Join Date
    Feb 2004
    Posts
    3,386
    Quote Originally Posted by homoludens View Post
    Yeah, fools rush in, or something like that. Sorry.

    The main reason I gave it any credence was Host X taking SSH offline, claiming they had all sorts of secret intell. I won't be moving my business there any time soon.



    Agreed.
    Unless Host X, is in the JPC Family why are you doing business with them at all....

    Traitor
    -------------------------
    the_ancient
    MP Technology Group

  9. #9
    Not A Senior Member homoludens's Avatar
    Join Date
    Sep 2005
    Location
    H-Town
    Posts
    582
    Quote Originally Posted by TA
    Traitor
    Coming from a member of His Majesty's Most Pernicious and Treacherous Rebel Colonies ...

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •