[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] ssh stopped working and can't login as root



PS: you installed ssh, but you didn't install the later security patch,
did you ?...

Something I noticed (finally) about the update .pkg, it defaults your sshd.config file to protocol 1 and 2. You need to go in and change this to only 1 and following Carrie B.'s directions, maybe change the port that ssh runs on.

I'm not sure, but it seems, since we've seen a couple of comprimses here that were done to systems that (maybe) had the update installed, that even with it in, if the system will fall back to protocol 1, then you may still be vulnerable.

How many of you are still using ttssh? If so, you're not using protocol 2, as ttssh will not run in 2. I changed my sshd.config file to only allow 2 and suddenly could not use ttssh any more, a quick look at their website shows they are unconcerned and have no planned update for the software to make it p-2 compatible. Also, winscp also will no longer work for secure file uploads for same reason. (I may have *what* those two programs do reversed since I've deleted them and don't really remember, and have been using putty, which does support p-2)

WS

_________________________________________________________________
MSN Photos is the easiest way to share and print your photos: http://photos.msn.com/support/worldwide.aspx