Slashdot Mirror


New ssh Exploit in the Wild

veg writes "In the last few hours there have been several reports of a new ssh bug, with an exploit seemingly in the wild. Oh god not again... The lengths some people will goto to try and damage Theo's pride." Update: 09/17 00:24 GMT by T : friscolr writes "Hot on the heels of rev 1 of the buffer.adv advisory, here is revision 2, which fixes more than revision 1 did. Also see the 3.7.1 release notes."

32 of 754 comments (clear)

  1. Uh oh by Anonymous Coward · · Score: 5, Funny

    Best patch and upgr..&*[NO CARRIER]

  2. Hooray! by TheQuantumShift · · Score: 1, Funny

    New manifestations of Job Security for us techs!

    --

    Shift happens. Fire it up.
  3. Public Service by Morologous · · Score: 5, Funny

    Posting this to slashdot is actually a public service, as the exploit description will be /.'d and unable to effectively be disseminated to the bad actors.

  4. Telnet by Henry+V+.009 · · Score: 5, Funny

    Thank god I'm using something secure like Telnet instead.

    1. Re:Telnet by fliplap · · Score: 2, Funny

      too bad you're running a stock Solaris installation!

    2. Re:Telnet by Anonymous Coward · · Score: 1, Funny

      if you want to save money you can just get a pair and then breed your own bandwidth.

  5. This is why I refuse to use ssh. by 91degrees · · Score: 1, Funny

    I mean really - telnet is perfectly secure unless you use a direct connection. Use of a quantum tunnelling encryption layer and probabilistic key generation means you get the maturity of telnet with a greater level of security (I'm talking non-recursive factorial strenth here).

    ssh is just for losers who can't set up teransparent network layering.

  6. bugs?? by maximum_high · · Score: 1, Funny

    Is it the same bug that requires me to type the full word "yes" or "no", and not shortcut keys 'y'/'n', when I want to connect to a remote server??

    =)

    1. Re:bugs?? by Anonymous Coward · · Score: 1, Funny

      Apparently so. If you type r00t! instead then SSH will connect to the remote server and log you in as the root user, without a password! Its amazing no one has noticed this before.

  7. guess who by dwakeman · · Score: 5, Funny

    Damn trinity and her sshnuke...

  8. I saw this exploit used by teamhasnoi · · Score: 5, Funny
    I was at the local library, and some kids were on a computer, talking loudly. They seemed to be rather excited about something.

    A librarian peeked around the corner to see where the noise was coming from, then put her finger to her lips and said, "Ssh!"

    The kids ignored her and kept talking, completely and utterly exploiting the hole, and circumventing the 'Ssh'!

    Never was I so frightened.

  9. Re:Suggestions for a newbie? by Anonymous Coward · · Score: 0, Funny

    There is no reason to be running SSH daemon on a desktop machine, especially one where you are always root. open a console and type 'netstat -a | grep ssh', if it's running mail Lindows support and tell them they are morons from AC on \.

  10. Re:Suggestions for a newbie? by Anonymous Coward · · Score: 1, Funny

    I'm afraid it means that everything you've installed so far is corrupt, and all your efforts have been wasted. Quickly now, go to your nearest office supply store, get a copy of Windows XP and start over, before the damage spreads!

  11. Obligatory programming joke by worst_name_ever · · Score: 1, Funny
    The lengths some people will goto

    Remember to use long jumps if you want to goto more than 255 bytes of pride-damaging.

    --

    In Soviet Rush, today's Tom Sawyer gets high on you.
  12. Re:Suggestions for a newbie? by p3d0 · · Score: 2, Funny
    tell them they are morons from AC on \.
    On backslashdot?
    --
    Patrick Doyle
    I mod down every jackass who puts his moderation policy in his sig. Oh, wait a sec....
  13. I fail to see.... by Damon+C.+Richardson · · Score: 1, Funny

    "disseminated to the bad actors." I fail to see what Burt Reynolds has to do with it.

    --

    Last one in jail is a fascist.
  14. Re:Ermm.. can anyone say "Microsoft" by Rhys · · Score: 1, Funny

    Ignoring the unix updating tools, it's hard to update.

    No kidding. Let me guess, ignoring the sun, it's dark?

    --
    Slashdot Patriotism: We Support our Dupes!
  15. WOW!! by narratorDan · · Score: 4, Funny

    I just read all these replies (about 15 right now) and all of them are nice and respectfull of the fact that this guy is a newbie!
    I must be on the wrong site.

    NarratorDan

    --
    "If you're not confused by quantum mechanics, you really don't understand it." - Niels Bohr
  16. Re:deceit by danormsby · · Score: 5, Funny

    Ssh, don't tell anyone.

    --
    Omnis amans amens
  17. Re:Does this effect Cygwin??? by funkman · · Score: 5, Funny

    You are already running windows. You have more serious problems.

  18. This is precisely... by devphil · · Score: 3, Funny


    ...why I always go back and add security holes to all of my programs. If some future (or current) anti-regime hacker needs to be able to break into a local power plant, I want to make sure my code can help!

    [I considered signing this post "love, Theo" but then thought better of it.]

    --
    You cannot apply a technological solution to a sociological problem. (Edwards' Law)
  19. Re:MOD PARENT DOWN by Syberghost · · Score: 5, Funny

    A demonstration would be nice.

    It'd serve you right if he gave you one. :-)

  20. Re:install base by ryanvm · · Score: 4, Funny

    The only really secure server is buried in concrete, unlugged and at the bottom of the deepest trench in the ocean. It's *probably* secure there, but I wouldn't bet my life on it.

    That's okay, I will.

    I bet this guy's life that a server on the bottom of the ocean is secure.

  21. Re:Uh oh - no funny by theLOUDroom · · Score: 4, Funny

    Yeah those "NO CARRIER" jokes just aren't fun@~%4!.z^%r#$% NO CARRIER

    --
    Life is too short to proofread.
  22. Re:Suggestions for a newbie? by metamatic · · Score: 2, Funny

    Something you seem to have missed is that Linux is open source, making it much easier to find exploitable holes. Imagine how many exploits would be uncovered in Windows if we could read the source code.

    In fact, you don't need to imagine it. Microsoft are on the record as stating that it's one of the reasons why they can't possibly reveal Windows source mode widely.

    --
    GCHQ Quantum Insert installed. If only our tongues were made of glass, how much more careful we would be when we speak
  23. Theres little time by JamesP · · Score: 2, Funny

    1. Make lsh incompatible w SCO UNIX
    2. ???
    3. WTF?
    4. Profit!!!

    --
    how long until /. fixes commenting on Chrome?
  24. Re:GOOD!! Red Hat, fix your RPMs!! by Zigg · · Score: 3, Funny

    I think you mean:

    Gentoo

    emerge ssh

    * GentooLamer has joined #gentoo
    <GentooLamer> recompiling ssh right now, got some good pr0n to watch in the meantime
    <fomit-instructions> yeah me too
    <gcc-O9> I'm out of pr0n I compiled KDE last week

  25. Re:Why all the lsh plugs? by Anonymous Coward · · Score: 1, Funny

    OpenSSH has a BSD-license, LSH has a GNU-license.

    It's must be a conspiracy by the GNU viral license advocates to wipe out "free"BSD licensed software!

  26. Re:See this comment for BSD patch and info by Jahf · · Score: 3, Funny

    don't you automatically trust flyingbuttmonkeys.com?

    --
    It is more productive to voice thoughtful opinions (reply) than to judge (moderate) others.
  27. Dr. Evil says... by Anonymous Coward · · Score: 1, Funny

    I've got a whole bag of Ssh with your name on it!
    That was a pre-emptive Ssh!

  28. Re:mod parent up please by mkldev · · Score: 2, Funny
    Or somebody rooted Neils's box due to an OpenSSH exploit.... :-D

    --
    120 character sigs suck. Make it 250.
  29. Re:not worried... by Anonymous Coward · · Score: 1, Funny

    have i mentioned you slashdot moderators can go fuck yourselves
    i cant get modded up if jesus came back with mod points