Re: Hacked stable system?

2001-11-07 Thread Gleb Arshinov
> "Justin" == Justin R Miller <[EMAIL PROTECTED]> writes: >> So, what could have caused ssh/telnet to hang like this while >> ftp worked fine? Justin> Check your local messages log and the remote one using the Justin> shell that you already have while you attempt a login. The

Re: Hacked stable system?

2001-11-07 Thread Gleb Arshinov
> "Jeff" == Jeff <[EMAIL PROTECTED]> writes: >> Yesterday, I noticed that I could no longer login using ssh or >> telnet. ssh logins would hang indefinitely whether I entered >> correct or incorrect passwords. Telnet logins would time-out >> after 60s. I tried different use

Re: Hacked stable system?

2001-11-07 Thread Lars Bahner
Gleb Arshinov wrote: > I am running an up-to-date stable distribution. It looks like it may > have been hacked yesterday, but I am not sure how. > So, what could have caused ssh/telnet to hang like this while ftp > worked fine? What else should I check for break-in signs? I am > thinking I s

Re: question about something, but don't know if it exists...

2001-11-07 Thread Vineet Kumar
* [EMAIL PROTECTED] ([EMAIL PROTECTED]) [011106 05:54]: > Hallo, > > > > > happen few times that students stole their passwords and so on and mainly > > > they could steal even teacher's these days.) > > > > Can you get a shell account on the outside of your local network? > > If so SSH over

Re: Hacked stable system?

2001-11-07 Thread Gleb Arshinov
> "Justin" == Justin R Miller <[EMAIL PROTECTED]> writes: >> So, what could have caused ssh/telnet to hang like this while >> ftp worked fine? Justin> Check your local messages log and the remote one using the Justin> shell that you already have while you attempt a login. Th

Re: Hacked stable system?

2001-11-07 Thread Gleb Arshinov
> "Jeff" == Jeff <[EMAIL PROTECTED]> writes: >> Yesterday, I noticed that I could no longer login using ssh or >> telnet. ssh logins would hang indefinitely whether I entered >> correct or incorrect passwords. Telnet logins would time-out >> after 60s. I tried different us

Re: Hacked stable system?

2001-11-07 Thread Wes Kurdziolek
Inline reply... -- Wes Kurdziolek Virginia Tech Computer Science Lab UNIX System Administrator E-mail: [EMAIL PROTECTED] GnuPG key: http://www.cslab.vt.edu/~wkurdzio/wkurdzio.asc On Wed, 7 Nov 2001, Gleb Arshinov wrote: > Yesterday, I noticed that I could no longer login using ssh or telnet. >

Re: Hacked stable system?

2001-11-07 Thread Justin R. Miller
Thus spake Gleb Arshinov ([EMAIL PROTECTED]): > /etc/passwd seems intact Have a look at /etc/shadow. I'm not sure if password changes touch /etc/passwd if you're using shadow passwords. Just a thought. > So, what could have caused ssh/telnet to hang like this while ftp > worked fine? Check

Re: Hacked stable system?

2001-11-07 Thread Wes Kurdziolek
Inline reply... -- Wes Kurdziolek Virginia Tech Computer Science Lab UNIX System Administrator E-mail: [EMAIL PROTECTED] GnuPG key: http://www.cslab.vt.edu/~wkurdzio/wkurdzio.asc On Wed, 7 Nov 2001, Gleb Arshinov wrote: > Yesterday, I noticed that I could no longer login using ssh or telnet. >

Re: Hacked stable system?

2001-11-07 Thread Jeff
Gleb Arshinov, 2001-Nov-07 16:10 -0800: > Yesterday, I noticed that I could no longer login using ssh or telnet. > ssh logins would hang indefinitely whether I entered correct or > incorrect passwords. Telnet logins would time-out after 60s. I tried > different users with the same result. Howeve

Re: Hacked stable system?

2001-11-07 Thread Justin R. Miller
Thus spake Gleb Arshinov ([EMAIL PROTECTED]): > /etc/passwd seems intact Have a look at /etc/shadow. I'm not sure if password changes touch /etc/passwd if you're using shadow passwords. Just a thought. > So, what could have caused ssh/telnet to hang like this while ftp > worked fine? Chec

Hacked stable system?

2001-11-07 Thread Gleb Arshinov
I am running an up-to-date stable distribution. It looks like it may have been hacked yesterday, but I am not sure how. Yesterday, I noticed that I could no longer login using ssh or telnet. ssh logins would hang indefinitely whether I entered correct or incorrect passwords. Telnet logins woul

Re: Hacked stable system?

2001-11-07 Thread Jeff
Gleb Arshinov, 2001-Nov-07 16:10 -0800: > Yesterday, I noticed that I could no longer login using ssh or telnet. > ssh logins would hang indefinitely whether I entered correct or > incorrect passwords. Telnet logins would time-out after 60s. I tried > different users with the same result. Howev

Hacked stable system?

2001-11-07 Thread Gleb Arshinov
I am running an up-to-date stable distribution. It looks like it may have been hacked yesterday, but I am not sure how. Yesterday, I noticed that I could no longer login using ssh or telnet. ssh logins would hang indefinitely whether I entered correct or incorrect passwords. Telnet logins wou

Re: Which ssh should I have?

2001-11-07 Thread Ville Uski
* Wichert Akkerman <[EMAIL PROTECTED]> [011107 18:54]: > That's because nessus only checks the version number, and since we > backported the patch we still have the old version number even though > we are safe. This also occurred to me, but appeared too trivial a solution... Well, I guess that's i

Re: Which ssh should I have?

2001-11-07 Thread David Wright
Quoting Ted Cabeen ([EMAIL PROTECTED]): > >Hm, why should I do that? Is my admin right when he thinks that my > >current sshd is vulnerable? I have the latest stable precompiled > >package, i.e. the default ssh installed. > > Make sure that you have the security site in your /etc/apt/sources.list

Re: Which ssh should I have?

2001-11-07 Thread Wichert Akkerman
Previously Ville Uski wrote: > Thanks for info. Yes, I have that line in my sources.list, and I also > believe I am fine. Our network admin used the nessus ssh plugin to scan > the network. He only says that nessus gives a warning about my computer > (concerning the crc bug) and knows nothing more

Re: Which ssh should I have?

2001-11-07 Thread Ville Uski
* Ted Cabeen <[EMAIL PROTECTED]> [011107 18:11]: > Make sure that you have the security site in your > /etc/apt/sources.list file. If you do, and apt-get update; apt-get > upgrade says you're up to date, then you're fine. In general, the > security team patches the current version to fix security

Re: Which ssh should I have?

2001-11-07 Thread Ted Cabeen
In message <[EMAIL PROTECTED]>, Ville Uski writes: >* jigal <[EMAIL PROTECTED]> [011107 14:20]: >> But I found this in the archives of the security mailinglist: >> http://lists.debian.org/debian-security/2001/debian-security-200102/msg00138 >.html >> >> The previous mail in the thread references t

Re: Which ssh should I have?

2001-11-07 Thread Ville Uski
* Wichert Akkerman <[EMAIL PROTECTED]> [011107 18:54]: > That's because nessus only checks the version number, and since we > backported the patch we still have the old version number even though > we are safe. This also occurred to me, but appeared too trivial a solution... Well, I guess that's

Re: Which ssh should I have?

2001-11-07 Thread Wichert Akkerman
Previously Ville Uski wrote: > Thanks for info. Yes, I have that line in my sources.list, and I also > believe I am fine. Our network admin used the nessus ssh plugin to scan > the network. He only says that nessus gives a warning about my computer > (concerning the crc bug) and knows nothing mor

Re: Which ssh should I have?

2001-11-07 Thread David Wright
Quoting Ted Cabeen ([EMAIL PROTECTED]): > >Hm, why should I do that? Is my admin right when he thinks that my > >current sshd is vulnerable? I have the latest stable precompiled > >package, i.e. the default ssh installed. > > Make sure that you have the security site in your /etc/apt/sources.lis

Re: Which ssh should I have?

2001-11-07 Thread Ville Uski
* Ted Cabeen <[EMAIL PROTECTED]> [011107 18:11]: > Make sure that you have the security site in your > /etc/apt/sources.list file. If you do, and apt-get update; apt-get > upgrade says you're up to date, then you're fine. In general, the > security team patches the current version to fix securit

Re: Which ssh should I have?

2001-11-07 Thread Ted Cabeen
In message <[EMAIL PROTECTED]>, Ville Uski writes: >* jigal <[EMAIL PROTECTED]> [011107 14:20]: >> But I found this in the archives of the security mailinglist: >> http://lists.debian.org/debian-security/2001/debian-security-200102/msg00138 >.html >> >> The previous mail in the thread references

Re: Which ssh should I have?

2001-11-07 Thread Ville Uski
* jigal <[EMAIL PROTECTED]> [011107 14:20]: > But I found this in the archives of the security mailinglist: > http://lists.debian.org/debian-security/2001/debian-security-200102/msg00138.html > > The previous mail in the thread references to: > http://razor.bindview.com/publish/advisories/adv_ssh1

Re: Which ssh should I have?

2001-11-07 Thread jigal
On Wed, 07 Nov 2001, jigal wrote: > Here you find a reference to the vuln, fixed. > http://www.debian.org/security/2001/dsa-027 I am sorry I found by reading it again it doesn't mention it. But I found this in the archives of the security mailinglist: http://lists.debian.org/debian-security/20

Re: Which ssh should I have?

2001-11-07 Thread jigal
On Wed, 07 Nov 2001, Ville Uski wrote: > The ssh package I currently have is ssh_1.2.3-9.3_i386.deb. > > I have understood that the crc32 bug was already found in February so I > find it hard to believe that it's not already fixed on debian (I'm > running woody on a laptop PC). I should have all

RE: Which ssh should I have?

2001-11-07 Thread Ed Street
Hello, www.freshmeat.net Or if your running debian do an apt-get install ssh (most recommended) Ed > -Original Message- > From: Osvaldo Mundim Junior [mailto:[EMAIL PROTECTED] > Sent: Wednesday, November 07, 2001 7:47 AM > To: debian-security@lists.debian.org > Subject: Re: Which ssh sh

Re: Which ssh should I have?

2001-11-07 Thread Osvaldo Mundim Junior
Where can I get the opensource ssh? tks On Wed, 07 Nov 2001, Ville Uski wrote: > Hi, > > I just joined the list after the admin of the network in my house had > complained that sshd running in my computer is "remotely exploitable". I > asked for more details and he only said it's the bug in the

Which ssh should I have?

2001-11-07 Thread Ville Uski
Hi, I just joined the list after the admin of the network in my house had complained that sshd running in my computer is "remotely exploitable". I asked for more details and he only said it's the bug in the crc32 bit. He also told me to install the newest version of openssh. The problem is now whi

Re: Which ssh should I have?

2001-11-07 Thread Ville Uski
* jigal <[EMAIL PROTECTED]> [011107 14:20]: > But I found this in the archives of the security mailinglist: > http://lists.debian.org/debian-security/2001/debian-security-200102/msg00138.html > > The previous mail in the thread references to: > http://razor.bindview.com/publish/advisories/adv_ssh

Re: Which ssh should I have?

2001-11-07 Thread jigal
On Wed, 07 Nov 2001, jigal wrote: > Here you find a reference to the vuln, fixed. > http://www.debian.org/security/2001/dsa-027 I am sorry I found by reading it again it doesn't mention it. But I found this in the archives of the security mailinglist: http://lists.debian.org/debian-security/2

Re: Which ssh should I have?

2001-11-07 Thread jigal
On Wed, 07 Nov 2001, Ville Uski wrote: > The ssh package I currently have is ssh_1.2.3-9.3_i386.deb. > > I have understood that the crc32 bug was already found in February so I > find it hard to believe that it's not already fixed on debian (I'm > running woody on a laptop PC). I should have al

RE: Which ssh should I have?

2001-11-07 Thread Ed Street
Hello, www.freshmeat.net Or if your running debian do an apt-get install ssh (most recommended) Ed > -Original Message- > From: Osvaldo Mundim Junior [mailto:[EMAIL PROTECTED]] > Sent: Wednesday, November 07, 2001 7:47 AM > To: [EMAIL PROTECTED] > Subject: Re: Which ssh should I have?

Re: Which ssh should I have?

2001-11-07 Thread Osvaldo Mundim Junior
Where can I get the opensource ssh? tks On Wed, 07 Nov 2001, Ville Uski wrote: > Hi, > > I just joined the list after the admin of the network in my house had > complained that sshd running in my computer is "remotely exploitable". I > asked for more details and he only said it's the bug in the

Which ssh should I have?

2001-11-07 Thread Ville Uski
Hi, I just joined the list after the admin of the network in my house had complained that sshd running in my computer is "remotely exploitable". I asked for more details and he only said it's the bug in the crc32 bit. He also told me to install the newest version of openssh. The problem is now wh

Re: question about something, but don't know if it exists...

2001-11-07 Thread Juha Jäykkä
> > mind is IPSec: make your firewall (or what ever) an IPSec gateway and > > run everything inside your network over IPSec. No more stealing, I > > would think. > Hmmm... I am afraid it isn't possible, because there are W95 > workstations. Or is there anything to support this which is reasonably

Re: question about something, but don't know if it exists...

2001-11-07 Thread Juha Jäykkä
> > mind is IPSec: make your firewall (or what ever) an IPSec gateway and > > run everything inside your network over IPSec. No more stealing, I > > would think. > Hmmm... I am afraid it isn't possible, because there are W95 > workstations. Or is there anything to support this which is reasonabl