D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] OpenSSH Vunrability



Rats do you remember what they said about mmap? 
Or better still where they said it? 
Here is the server watching me log back in from an unpatched
box, to my nice shiny new sshd.

Oh and remember to restart the sshd after applying the fix -
<doh> - for those catching up privsep has it's own README in the
new source tar ball, you have to make an empty chroot jail and
user.....yawn.

# sshd -d -d -d -e
debug1: sshd version OpenSSH_3.3
debug1: private host key: #0 type 0 RSA1
debug3: Not a RSA1 key file /usr/local/etc/ssh_host_rsa_key.
debug1: read PEM private key done: type RSA
debug1: private host key: #1 type 1 RSA
debug3: Not a RSA1 key file /usr/local/etc/ssh_host_dsa_key.
debug1: read PEM private key done: type DSA
debug1: private host key: #2 type 2 DSA
debug1: Bind to port 22 on 192.168.0.1.
Server listening on 192.168.0.1 port 22.
debug1: Bind to port 22 on 192.168.1.1.
Server listening on 192.168.1.1 port 22.
debug1: Bind to port 22 on 127.0.0.1.
Server listening on 127.0.0.1 port 22.
Generating 768 bit RSA key.
RSA key generation complete.
debug1: Server will not fork when running in debugging mode.
Connection from 192.168.0.3 port 1035
debug1: Client protocol version 1.5; client software version
OpenSSH_2.9p2
debug1: match: OpenSSH_2.9p2 pat
OpenSSH_2.*,OpenSSH_3.0*,OpenSSH_3.1*
debug1: Local version string SSH-1.99-OpenSSH_3.3
mmap(65536): Invalid argument
debug1: Calling cleanup 0x806a8ec(0x0)
[root@xxxxxx /root]#

--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly