D&C Lug - Home Page
Devon & Cornwall Linux Users' Group

[ Date Index ][ Thread Index ]
[ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] ISS Advisory: OpenSSH Remote Challenge Vulnerability



Theo Zourzouvillys wrote:

so it turns out if you have ChallengeResponseAuthentication set to no, SSH
ain't vunrable

Grr - that'll do as a fix on the other machine till Mandrake
catch up.

I'm curious though - shutting down unused authentication
mechanism sounds a good idea - but I don't want to become too
much of a OpenSSH guru to secure it.

Anyone seen a good explanation?

--
The Mailing List for the Devon & Cornwall LUG
Mail majordomo@xxxxxxxxxxxx with "unsubscribe list" in the
message body to unsubscribe.


Lynx friendly