Koozali.org: home of the SME Server

RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable

trakker

RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
« on: February 09, 2005, 07:45:42 PM »
RKHunter states
apache 1.3.27
gnupg 1.0.7
openssl 0.9.6b
and
proftp 1.2.9

are vulnerable, but I can't seem to find any updates for these (or info regarding the vulnerability either)

Any help here?

Thanks

Trakker

trakker

updates
« Reply #1 on: February 09, 2005, 08:04:11 PM »
Just found a new update script (these forums)

Thanks

Trakker

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
« Reply #2 on: February 09, 2005, 09:00:52 PM »
Quote from: "trakker"
RKHunter states
apache 1.3.27
gnupg 1.0.7
openssl 0.9.6b
and
proftp 1.2.9

are vulnerable, but I can't seem to find any updates for these (or info regarding the vulnerability either)


RKHunter could be wrong. It very likely is wrong if it is depending just on version numbers to infer that software is vulnerable. All of those packages you have identified have had various patches applied. And gnupg isn't even used.

If you ever think you've discovered a security vulnerability, send mail to security@contribs.org. That way contribs.org have a chance to fix it before you tell the world about the problem. Or they get a chance to explain to you why there isn't a problem.

trakker

not intended....
« Reply #3 on: February 09, 2005, 09:07:12 PM »
Thanks Charlie,

didn't mean to blab to the world about a supposed vulnerability...

Am relatively new to Linux (but have been using SME since version 5 (2 x Dell 650's in business setting))

again, my apologies....

Trakker

Offline slords

  • *****
  • 235
  • +3/-0
RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
« Reply #4 on: February 09, 2005, 11:55:24 PM »
rkhunter is such a load of #$&%#$!!  All it does is scan your system for packages and compares it to a list of version numbers.  If it doesn't match the latest version then it says you are vulnerable.

What it shoul really be called is "checkforlatestversion".  That is all it really does.

-Shad
"Programming today is a race between software engineers striving to build bigger and better idiot-proof programs,
and the Universe trying to produce bigger and better idiots. So far, the Universe is winning." -- Rich Cook

Offline marsa_matruh

  • *****
  • 250
  • +0/-0
Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
« Reply #5 on: February 10, 2005, 10:12:14 AM »
Quote from: "CharlieBrady"
Or they get a chance to explain to you why there isn't a problem.


In that case, can you also put the answer somewhere on contribs.org website? So, everybody can know that there is no need to upgrade apache, gnupg, openssl, proftp, php and some more ...

(May be, nobody is doing security reports)

duncan

Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
« Reply #6 on: February 10, 2005, 10:27:49 AM »
Quote from: "marsa_matruh"
Quote from: "CharlieBrady"
Or they get a chance to explain to you why there isn't a problem.


In that case, can you also put the answer somewhere on contribs.org website? So, everybody can know that there is no need to upgrade apache, gnupg, openssl, proftp, php and some more ...

(May be, nobody is doing security reports)


Its been mentioned in the forums more than once.

mbachmann

Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
« Reply #7 on: February 10, 2005, 11:12:23 AM »
Quote from: "marsa_matruh"
In that case, can you also put the answer somewhere on contribs.org website?


I did: http://no.longer.valid/phpwiki/index.php/SecurityFAQ#rkunter

trakker

poking the hornets nest
« Reply #8 on: February 10, 2005, 05:05:14 PM »
Wow, seems I've provoked er pushed/punched a few buttons here....  

note to self: disregard rkhunter vulnerabilities listing.

Trakker

Offline mdo

  • *
  • 355
  • +0/-0
RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
« Reply #9 on: February 10, 2005, 06:58:18 PM »
You could also change /etc/cron.daily/rkhunter (or it's template) and add "skip-application-check".

my $command='/usr/local/bin/rkhunter --skip-application-check --cronjob'.(FULL_REPORT?'':' --quiet');

Regards,
Michael
...

Offline CharlieBrady

  • *
  • 6,918
  • +3/-0
RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
« Reply #10 on: February 11, 2005, 12:01:49 AM »
Quote from: "slords"
rkhunter is such a load of #$&%#$!!  All it does is scan your system for packages and compares it to a list of version numbers.  If it doesn't match the latest version then it says you are vulnerable.

What it shoul really be called is "checkforlatestversion".  That is all it really does.


No, that's not all it does. It also searches for real evidence that a system has been compromised, looking for various telltale signs, such as known cracking tools, and hidden temporary directories. So it's not as bad as you think it is, and not as good as others would make out.

alexsmithmcp

RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
« Reply #11 on: February 11, 2005, 09:24:40 AM »
but this is indeed what catches alot of people. i belive it is because redhat/fedora backport there patches to older versions of software and dont change the version numbers. if your worryed about security of packages best thing you could do is join one of the security mailing lists for the distro your using :)