Koozali.org: home of the SME Server

SSH CRC32 attack detection code contains remote integer over

Doyle Glaze

SSH CRC32 attack detection code contains remote integer over
« on: November 19, 2001, 07:53:46 PM »
Has anyone address the possible problem with ssh1 and the 'Limpninja' Trojan horse.

Threads on security newsgroups have suggested that hackers may be breaking into Linux boxes running the SSH1 protocol, using a known vulnerability in the SSH CRC32 (cyclic redundancy checksum) that was published late last month.

Please info us if this is a problem with version 4 and 5 of e-smith.

Thanks
Doyle Glaze
dpg@mistec.com