[ale] ssh remote root exploit :-(

John Mills jmmills at telocity.com
Tue Jun 25 19:03:27 EDT 2002


Pizza -

On Tue, 25 Jun 2002, Stuffed Crust wrote:

> On Tue, Jun 25, 2002 at 04:33:54PM -0400, John Mills wrote:
> > > It is worth mentioning that as it stands, 2.2 kernels will not work with
> > > openssh 3.3 unless you disable compression.  
> > How do I do that?
 
> in /etc/ssh/sshd_config
> add a line which says:
 
> Compression no

Thanks - that did it. I need to test more thoroughly, but right now I am
running openssh-3.3p1 from sources, with:

Compression no
UsePrivilegeSeparation yes

Local and LAN logins are fine. I may go ahead and install the RPM you so
promptly provided (for administrative clarity), but at least I've done
what was suggested.

 - John Mills


---
This message has been sent through the ALE general discussion list.
See http://www.ale.org/mailing-lists.shtml for more info. Problems should be 
sent to listmaster at ale dot org.






More information about the Ale mailing list