Debian fumble jeopardizes all sshd-equipped servers

  2008-05-17 05:30:02
As has been widely reported, the maintainers of Debian's OpenSSL packages made some errors recently that have potentially compromised the security of any sshd-equipped system used remotely by Debian users. System administrators may wish to purge authorized_key files of public keys generated since 2006 by affected client machines. Simply using a Debian-based machine to access a remote server via SSH would not be enough to put the machine at risk. However, if the user copied a public key generated on a Debian-based system to the remote server, for example to take advantage of the higher security offered by password-free logins, then the weak key could make the server susceptible to brute-force attacks, especially if the user's name is easily guessable. 
  PNG Image  PNG Image  PNG Image




This particular article has been collected via RSS syndication. We apologize if it's too brief.
If You wish to publish articles on LinuxStreet.net please contact us.




  Similar articles  
ImageDebian& APT - Why I love it
ImageDebian GNU/Linux 3.0 archived
ImageDebian Weekly News - March 13th, 2007
ImageCrystal balls with HP
ImageOf hypocrisy and the FSF
ImageInstalling And Using OpenVZ On Debian Etch
ImageDebian Weekly News - April 24th, 2007
ImageBrazil's SERPRO Chooses Debian; Wishes to Collaborate
ImageHow To Block Spammers/Hackers With mod_defensible On Apache2 (Debian Etch)
ImageRetrieving Emails From Remote Servers With fetchmail (Debian Etch)

  Related tags  
Debian   Server   System   User   Public   Machine   Security   Remote   SSH   Attacks   Advantage   Example   Packages   Servers   Authorized   Client   Administrators   Users  

Leave a comment on this article


Captcha

  
Check this if the code you see is not readable and resubmit the form.
(Data you entered will be preserved)



  

Comments (0)