Rookit infections: AARRGH!

Fred puissante at biz.puissante.com
Mon May 9 09:48:00 EDT 2005


On Mon, 2005-05-09 at 09:23 -0400, Tom Buskey wrote:
> 
> 3.  Do not allow SSH v1 protocol.  Only allow v2.  v1 has known,
> unfixable, vulnerabilities.

Yes, I have been turning off V1 on the boxes under attack. Though from
now on, V1 will *always* be disabled. Why it is still left enabled by
the various distros given the vulnerabilities is beyond me.

-Fred




More information about the gnhlug-discuss mailing list