| Emails | ||
|---|---|---|
----- Forwarded message from Planet Debian -----
From: Planet Debian http://blog.drinsama.de/erich/en/linux/2008051401-consequences-of-sslssh-weakness.html Erich Schubert -- Consequences of the SSH/SSL weakness
Let me just point out, that the consequences affect all users of
I'll go into the details of the security issues below, but let me
Apparently, there are only about 2^15 different keys generated by
Hackers have already generated all these 32000 different keys, for
So we now have about 32000 keys which are used by lots of Debian
The key is used to log into a system without a password. Sometimes
Sometimes (or let me even claim 'often') one such key is also used
Now the weakness is introduced by the client, not by the server.
In fact, if your server is running Debian and you installed the
*Fixing the bad key-generation is just half of the deal.
Let me just repeat this: *Any Linux/Unix/*BSD system is vulnerable
Note that if you are not careful, you might lock yourself out from 09:43pm[1]
Links:
-- ----- End forwarded message -----
--
-------------- nächster Teil -------------- |
