Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] Debian OpenSSL critical security bug
- Date: Tue, 20 May 2008 02:50:56 +0200
- From: Christian Horn <chorn@example.com>
- Subject: Re: [tlug] Debian OpenSSL critical security bug
- References: <4fefd6340805131436p641e9605k84954b75accb8e2e@mail.gmail.com> <d8fcc0800805131552g4d1d0324me48d16a82980af33@mail.gmail.com> <78d7dd350805182328u6986e426o6538a5f6cf1fcc74@mail.gmail.com> <20080519063609.GA6117@fluxcoil.net> <87abimf6jn.fsf@uwakimon.sk.tsukuba.ac.jp>
- User-agent: Mutt/1.5.13 (2006-08-11)
On Tue, May 20, 2008 at 04:16:44AM +0900, Stephen J. Turnbull wrote: > Christian Horn writes: > > > And after 90minutes of bruteforcing rsa-keys i could login from the outside. > > You mean simply with for i in lots of numbers; ssh-keygen key$i; do > try login with new key; lather; rinse; done? Exactly. Ok, guessing the username has also to happen, wondering what percentage of internethosts allows direct root-login via ssh. > No wonder I've seen a > sudden increase in traffic from China! (What I'm seeing is not a > problem, it's the SYN packets that are being filtered.) http://stats.denyhosts.net/stats.html Interestingly its said that debian updated the packages 5 days bevore the flaw was published, and indeed there is a small peak.. Christian
- Follow-Ups:
- Re: [tlug] Debian OpenSSL critical security bug
- From: Curt Sampson
- References:
- [tlug] Debian OpenSSL critical security bug
- From: Gernot Hassenpflug
- Re: [tlug] Debian OpenSSL critical security bug
- From: Josh Glover
- Re: [tlug] Debian OpenSSL critical security bug
- From: Hung Nguyen Vu
- Re: [tlug] Debian OpenSSL critical security bug
- From: Christian Horn
- Re: [tlug] Debian OpenSSL critical security bug
- From: Stephen J. Turnbull
Home | Main Index | Thread Index
- Prev by Date: Re: [tlug] OT: interesting NY times article:High-Tech Japanese, Running Out of Engineers
- Next by Date: Re: [tlug] OT: interesting NY times article:High-Tech Japanese, Running Out of Engineers
- Previous by thread: Re: [tlug] Debian OpenSSL critical security bug
- Next by thread: Re: [tlug] Debian OpenSSL critical security bug
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links