Berkeley CSUA MOTD:Entry 14887
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2024/11/23 [General] UID:1000 Activity:popular
11/23   

1998/11/3-4 [Computer/SW/Security] UID:14887 Activity:high
11/3    Is the latest ssh bug really worth deinstalling it?  My friend and
        I are having an arguement over this point. A URL on the subject:
        http://news.freshmeat.net/readmore?f=ssh-vulnerability  --ssh h0zer
        \_ No definetly exploitable vulnerability has been found yet
            Until one is, you're much better off using it than not
            \_ Your machine is safer with no login mechanisms, not even
               ssh.   In fact, its even more secure if you unplug it from
               the net, unplug it from power, lock it in a safe, and bury
            \_ Your machine is safer with no login mechanisms, not eve
                \_ But even then your host can still be easily compromised
                   through the use of brute-force methods.  If you're really
                   concerned, the best solution is to not buy a computer at
               ssh.   In fact, its even more secure if you unplug it fro
               the net, unplug it from power, lock it in a safe, and bur
               that safe beneath your home
                   \_ but then I miss out on all the cash I get from
                \_ But even then your host can still be easily compromise
            \_ IBM has specially denied the assertion that it had ever
               uncovered an exploitable bug in ssh, and is complaining
               about rootshell's unethical use of a minor advisory which
               does not appear to detail any real security threat.  So the
                   through the use of brute-force methods.  If you're reall
                   concerned, the best solution is to not buy a computer a
                   all.  Go outside and enjoy the blue sky and sunshine -
                   you'll have all that extra pocket cash to take with you
                   \_ fresh air smells funny. i think i'll stay inside soda
                   \_ but then I miss out on all the cash I get fro
                      cracking other peoples' ssh-guarded firewalls
            \_ IBM has specially denied the assertion that it had eve
               uncovered an exploitable bug in ssh, and is complainin
               about rootshell's unethical use of a minor advisory whic
               does not appear to detail any real security threat.  So th
               people who supposedly found the bug say there is none
2024/11/23 [General] UID:1000 Activity:popular
11/23   

You may also be interested in these entries...
2012/8/26-11/7 [Computer/SW/Security] UID:54465 Activity:nil
8/26    Poll: how many of you pub/priv key users: 1) use private keys that
        are not password protected 2) password protect your private keys
        but don't use ssh-agent 3) use ssh-agent:
        1) .
        2) ..
        3) ...
	...
2012/9/24-11/7 [Computer/SW/Languages, Computer/SW/Unix] UID:54484 Activity:nil
9/24    How come changing my shell using ldapmodify (chsh doesn't work) doesn't
        work either? ldapsearch and getent show the new shell but I still get
        the old shell on login.
        \_ Scratch that, it magically took my new shell now. WTF?
           \_ probably nscd(8)
	...
2012/8/7-10/17 [Computer/SW/Security] UID:54455 Activity:nil
8/6     Amazon and Apple have lame security policies:
        http://www.wired.com/gadgetlab/2012/08/apple-amazon-mat-honan-hacking/all
        "First you call Amazon and tell them you are the account holder, and
         want to add a credit card number to the account. All you need is the
         name on the account, an associated e-mail address, and the billing
         address. "
	...
2012/7/18-8/19 [Health/Men, Computer/SW/Security] UID:54438 Activity:nil
7/18    "Largest penis record holder arouses security suspicions at airport"
        http://www.csua.org/u/x2f (in.news.yahoo.com)
        \_ I often have that same problem.
        \_ I think the headline writer had some fun with that one.
           \_ One time when I glanced over a Yahoo News headline "U.S. busts
              largest-ever identity theft ring" all I saw was "U.S. busts
	...
2012/4/23-6/1 [Computer/SW/WWW/Browsers] UID:54360 Activity:nil
4/19    My Firefox 3.6.28 pops up a Software Update box that reads "Your
        version of Firefox will soon be vulnerable to online attacks."  Are
        they planning to turn off some security feature in my version of
        Firefox?
        \_ Not as such, no, but they're no longer developing this version,
           so if a 3.6.x-targeted hack shows up, you're not going to get
	...
2011/11/8-30 [Computer/SW/Security, Computer/SW/OS/Windows] UID:54218 Activity:nil
11/8    ObM$Sucks
        http://technet.microsoft.com/en-us/security/bulletin/ms11-083
        \_ How is this different from the hundreds of other M$ security
           vulnerabilities that people have been finding?
           \_ "The vulnerability could allow remote code execution if an
               attacker sends a continuous flow of specially crafted UDP
	...
2011/11/11-30 [Computer/SW/Security] UID:54224 Activity:nil
11/11   MacOSX's Sandbox security hole:
        http://preview.tinyurl.com/7ph2wtg [arstechnica]
	...
Cache (67 bytes)
news.freshmeat.net/readmore?f=ssh-vulnerability
Not Found The requested URL /readmore was not found on this server.