Koozali.org: home of the SME Server

Legacy Forums => Experienced User Forum => Topic started by: trakker on February 09, 2005, 07:45:42 PM

Title: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
Post by: trakker on February 09, 2005, 07:45:42 PM
RKHunter states
apache 1.3.27
gnupg 1.0.7
openssl 0.9.6b
and
proftp 1.2.9

are vulnerable, but I can't seem to find any updates for these (or info regarding the vulnerability either)

Any help here?

Thanks

Trakker
Title: updates
Post by: trakker on February 09, 2005, 08:04:11 PM
Just found a new update script (these forums)

Thanks

Trakker
Title: Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
Post by: CharlieBrady on February 09, 2005, 09:00:52 PM
Quote from: "trakker"
RKHunter states
apache 1.3.27
gnupg 1.0.7
openssl 0.9.6b
and
proftp 1.2.9

are vulnerable, but I can't seem to find any updates for these (or info regarding the vulnerability either)


RKHunter could be wrong. It very likely is wrong if it is depending just on version numbers to infer that software is vulnerable. All of those packages you have identified have had various patches applied. And gnupg isn't even used.

If you ever think you've discovered a security vulnerability, send mail to security@contribs.org. That way contribs.org have a chance to fix it before you tell the world about the problem. Or they get a chance to explain to you why there isn't a problem.
Title: not intended....
Post by: trakker on February 09, 2005, 09:07:12 PM
Thanks Charlie,

didn't mean to blab to the world about a supposed vulnerability...

Am relatively new to Linux (but have been using SME since version 5 (2 x Dell 650's in business setting))

again, my apologies....

Trakker
Title: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
Post by: slords on February 09, 2005, 11:55:24 PM
rkhunter is such a load of #$&%#$!!  All it does is scan your system for packages and compares it to a list of version numbers.  If it doesn't match the latest version then it says you are vulnerable.

What it shoul really be called is "checkforlatestversion".  That is all it really does.

-Shad
Title: Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
Post by: marsa_matruh on February 10, 2005, 10:12:14 AM
Quote from: "CharlieBrady"
Or they get a chance to explain to you why there isn't a problem.


In that case, can you also put the answer somewhere on contribs.org website? So, everybody can know that there is no need to upgrade apache, gnupg, openssl, proftp, php and some more ...

(May be, nobody is doing security reports)
Title: Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
Post by: duncan on February 10, 2005, 10:27:49 AM
Quote from: "marsa_matruh"
Quote from: "CharlieBrady"
Or they get a chance to explain to you why there isn't a problem.


In that case, can you also put the answer somewhere on contribs.org website? So, everybody can know that there is no need to upgrade apache, gnupg, openssl, proftp, php and some more ...

(May be, nobody is doing security reports)


Its been mentioned in the forums more than once.
Title: Re: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulner
Post by: mbachmann on February 10, 2005, 11:12:23 AM
Quote from: "marsa_matruh"
In that case, can you also put the answer somewhere on contribs.org website?


I did: http://no.longer.valid/phpwiki/index.php/SecurityFAQ#rkunter
Title: poking the hornets nest
Post by: trakker on February 10, 2005, 05:05:14 PM
Wow, seems I've provoked er pushed/punched a few buttons here....  

note to self: disregard rkhunter vulnerabilities listing.

Trakker
Title: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
Post by: mdo on February 10, 2005, 06:58:18 PM
You could also change /etc/cron.daily/rkhunter (or it's template) and add "skip-application-check".

my $command='/usr/local/bin/rkhunter --skip-application-check --cronjob'.(FULL_REPORT?'':' --quiet');

Regards,
Michael
Title: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
Post by: CharlieBrady on February 11, 2005, 12:01:49 AM
Quote from: "slords"
rkhunter is such a load of #$&%#$!!  All it does is scan your system for packages and compares it to a list of version numbers.  If it doesn't match the latest version then it says you are vulnerable.

What it shoul really be called is "checkforlatestversion".  That is all it really does.


No, that's not all it does. It also searches for real evidence that a system has been compromised, looking for various telltale signs, such as known cracking tools, and hidden temporary directories. So it's not as bad as you think it is, and not as good as others would make out.
Title: RKHunter say Apache/GNUPG/OPENSSL and ProFTPd are vulnerable
Post by: alexsmithmcp on February 11, 2005, 09:24:40 AM
but this is indeed what catches alot of people. i belive it is because redhat/fedora backport there patches to older versions of software and dont change the version numbers. if your worryed about security of packages best thing you could do is join one of the security mailing lists for the distro your using :)