Rookit infections: AARRGH!
    Fred 
    puissante at biz.puissante.com
       
    Mon May  9 09:48:00 EDT 2005
    
    
  
On Mon, 2005-05-09 at 09:23 -0400, Tom Buskey wrote:
> 
> 3.  Do not allow SSH v1 protocol.  Only allow v2.  v1 has known,
> unfixable, vulnerabilities.
Yes, I have been turning off V1 on the boxes under attack. Though from
now on, V1 will *always* be disabled. Why it is still left enabled by
the various distros given the vulnerabilities is beyond me.
-Fred
    
    
More information about the gnhlug-discuss
mailing list