Vanwege de ondekte exploit in ssh-server wil ik m'n ssh gaan updaten.
Hoe kom ik erachter welke versie er nu draait?
Hoe kom ik erachter welke versie er nu draait?
Don't worry, it's all just 1's and 0's.
Over de exploit zoals die gepost is op bugtraq, door Hugo Dias met subject SH CRC-32 Compensation Attack Detector Vulnerability Exploit.Op woensdag 21 februari 2001 15:23 schreef Neelix het volgende:
Dan ben ik wel benieuwd over wat voor exploit je het dan hebt eigenlijk....
Ofwel: het is meer een soort proof-of-concept dan een echte exploit. En volgens mij is dit een andere bug dan de "SSH1 key recovery" of vergis ik me nuWe need to know several numbers for it to work so it's very difficult to use the exploit on the wild.
[..]
We need to be rootfor doing this ... Finding the numbers we need without being root is very difficult. And without no access to any user in the system at all its even more difficult. This addresses changes with the plataform,operating system,packet length...
BUT its possible to do it (pheraps by reproducing exactly the victim environment)
and thats why i wrote this.
So as allways : "Please upgrade your software"