Slashdot Mirror


Slashback: OpenSSH, Bio, Timeliness

Welcome to Slashback, with updates (below) on a handful of recent Slashdot posts. Most importantly, a message regarding OpenSSH 3.3 could save your system from attack -- read it; you might need to pass the word on to your vendor, too.

Things that make you want to bring back thumbscrews. A few days ago, we mentioned the release of OpenSSH 3.3; compared to previous versions, the biggest change in 3.3 is increased emphasis on privilege separation. Today, Theo de Raadt sent word of an OpenSSH vulnerability being worked on by ISS and the OpenBSD team, details of which are expected to be published early next week.

In an announcement sent to bugtraq, he wrote: "However, I can say that when OpenSSH's sshd(8) is running with priv separation, the bug cannot be exploited.

OpenSSH 3.3p was released a few days ago, with various improvements but in particular, it significantly improves the Linux and Solaris support for priv sep. However, it is not yet perfect. Compression is disabled on some systems, and the many varieties of PAM are causing major headaches.

However, everyone should update to OpenSSH 3.3 immediately, and enable priv separation in their ssh daemons, by setting this in your /etc/ssh/sshd_config file:

UsePrivilegeSeparation yes

Depending on what your system is, privsep may break some ssh functionality. However, with privsep turned on, you are immune from at least one remote hole. Understand?

3.3 does not contain a fix for this upcoming bug.

If priv separation does not work on your operating system, you need to work with your vendor so that we get patches to make it work on your system. Our developers are swamped enough without trying to support the myriad of PAM and other issues which exist in various systems. You must call on your vendors to help us."

Theo emphasizes the role of vendor cooperation in making privilege separation work on the full range of systems on which OpenSSH runs. "If the vendors don't start pulling their part," he says in an email, "by the time the bug is posted their customers will be left unprotected. These vendors who do not do the right job and instead just 'sell sell sell' are starting to become annoying. On a lot of systems today, privsep does NOT work well at all. The vendors have not been helping!"

A patched version of OpenSSH could be released as soon as Friday, incorporating vendor patches received by this Thursday.

Read More on Stallman. Vamphyri writes: "Sam Williams, author of 'Free as in Freedom', biography of GNU/Linux founder Richard M. Stallman has gone live with the online free version 1.0 of FAIFzilla.org. The paper pulp version publishers O'Reilly & Associates agreed under the terms of the GNU Free Document License and have their own version up at their site. Williams' site allows for content and corrections to be submitted by readers. He hopes for contributions to be included in later editions of the O'Reilly bio. Also: CGI coders wanted for site enhancement, paragraph and line numbering, searches etc. Maybe a CVS Tree is in order? :)"

"Urpmi Norton" doesn't work for some reason. MrResistor writes "Upon logging in to my computer at work this morning, I was greeted by a virus update notice from McAfee SecurityCenter. The update for today includes W97M/Melissa@MM, and of course McAfees newly manuf^H^H^H^H^Hdiscovered threat, the W32/Perrun JPEG virus (which was also highlighted in yesterdays update). All of the updates in the last week or so have been rated Low or No Threat (except for Perrun, which is "Low On Watch". It seems that in addition to manufacturing new threats, they're also rehashing old threats to keep subscription renewals up. Perhaps it's time for Slashdot to add an Ethics topic?"

9 of 373 comments (clear)

  1. Here's an amateur quickie... by Anonymous Coward · · Score: 0, Offtopic

    News.com did an interview with CmdrTaco.

  2. Ethics Topic? by Ex-Parrot · · Score: 1, Offtopic

    I don't think I need or want Slashdot to tell me what is or isn't ethical.

    --
    To many, total abstinence is easier than perfect moderation. -- St. Augustine
  3. Re:Ethics Topic? by Lemmy+Caution · · Score: 1, Offtopic

    Then they don't need or want you telling them that it isn't ethical for them to tell you what is or isn't ethical.

  4. Link goes to interview by sideshow · · Score: 0, Offtopic

    and does not redirect to goatse.

    --

    Hollow words will burn and hollow men will burn.

  5. Answer to the banner advert I got on this page: by Graspee_Leemoor · · Score: 0, Offtopic

    Q: "Where do Linux Experts go when they need Windows Hosting ?"

    A: A mental institution.

    Thank you very much for reading, and a sweet good-night to all.

    graspee

  6. RedHat 7.0-7.2 Errata by peterdaly · · Score: 1, Offtopic

    RedHat has an OpenSSH errata security fix from 5/22 HERE. Anyone know if this is the bug in question?

    -Pete

  7. Re:The Alternative to OpenSSH or SSH (commerical) by Tadghe · · Score: 1, Offtopic

    Flamebait?

    I *really* fail to see how this is flamebait... For that I would (IMHO) had to add in a few comments like *BSD is dead (not as far as I can tell)....

    --
    Bugs Bunny was right.
  8. Ethics? by NanoGator · · Score: 1, Offtopic

    "Perhaps it's time for Slashdot to add an Ethics topic?"

    I'd appreciate it. I'd submit an article on some of the moderations I've recieved lately. Heh.

    --
    "Derp de derp."
  9. Re: offtopic (been warned) by fferreres · · Score: 0, Offtopic
    Moderation is not a measure of how much you agree with someone's post.

    I know, that's true. But then what does insightfull mean? Or interesting? If you don't agree something is interesting then why should it be? If you don't think it's insightfull (and you actually think it's real bullshit) how can you leave it like that?

    It's very difficult to walk the thin line between:

    Ok, i don't agree or find it usefull, but maybe someone else does so i don't metamod

    Mh, it's full of crap (or trivial)

    Anyway, i guess modding up and only ridicule cases down is what's best (for me)...

    --
    unfinished: (adj.)