ssh exploit

Pagina: 1
Acties:
  • 111 views sinds 30-01-2008
  • Reageer

  • xantos
  • Registratie: Juni 1999
  • Niet online
Vanwege de ondekte exploit in ssh-server wil ik m'n ssh gaan updaten.

Hoe kom ik erachter welke versie er nu draait?

  • RvdH
  • Registratie: Juni 1999
  • Laatst online: 28-07 15:42

RvdH

Uitvinder van RickRAID

telnet localhost 22

  • xantos
  • Registratie: Juni 1999
  • Niet online
Thnx..

  • Neelix
  • Registratie: Oktober 1999
  • Laatst online: 24-03 11:03
Dan ben ik wel benieuwd over wat voor exploit je het dan hebt eigenlijk....

Don't worry, it's all just 1's and 0's.


  • Bigs
  • Registratie: Mei 2000
  • Niet online
Volgens mij bedoel je met exploit gewoon het probleem dat in het hele SSH1 protocol zit of niet?

  • xantos
  • Registratie: Juni 1999
  • Niet online
Misschien druk ik me een beetje verkeerd uit. http://www.securityfocus.com/bid/2347

Als trouwens een telnet doe naar poort 22 dan zie ik:
SSH-1.99-OpenSSH_2.2.0p1

Welke versie heb ik dan nu draaien 1.99 of 2.2.0p1 ??

  • mavink
  • Registratie: April 2000
  • Laatst online: 27-05 09:16
Die tweede is het echte versienummer. Volgens mij staat dat 1.99 er alleen omdat hij *ook* ssh1 support heeft en sommige clients anders in de war raken.

  • serkoon
  • Registratie: April 2000
  • Niet online

serkoon

mekker.

Op woensdag 21 februari 2001 15:23 schreef Neelix het volgende:
Dan ben ik wel benieuwd over wat voor exploit je het dan hebt eigenlijk....
Over de exploit zoals die gepost is op bugtraq, door Hugo Dias met subject SH CRC-32 Compensation Attack Detector Vulnerability Exploit.

  • mavink
  • Registratie: April 2000
  • Laatst online: 27-05 09:16
Een paar quotes:
We need to know several numbers for it to work so it's very difficult to use the exploit on the wild.

[..]

We need to be root :) for doing this ... Finding the numbers we need without being root is very difficult. And without no access to any user in the system at all its even more difficult. This addresses changes with the plataform,operating system,packet length...

BUT its possible to do it (pheraps by reproducing exactly the victim environment)
and thats why i wrote this.

So as allways : "Please upgrade your software"
Ofwel: het is meer een soort proof-of-concept dan een echte exploit. En volgens mij is dit een andere bug dan de "SSH1 key recovery" of vergis ik me nu :?
Pagina: 1