Recent breakins / SSHD root hole?

Wichert Akkerman wichert at valinux.com
Tue Jun 5 05:46:11 EST 2001


Previously nuuB wrote:
> No, I don't think so. AFAIK that bug was fixed in 2.1.1, and apache.org
> reportedly ran "OpenSSH 2.2".

apache.org never had an insecure ssh, someone knew a password for an
account and used that.

Wichert.

-- 
  _________________________________________________________________
 /       Nothing is fool-proof to a sufficiently talented fool     \
| wichert at cistron.nl                  http://www.liacs.nl/~wichert/ |
| 1024D/2FA3BC2D 576E 100B 518D 2F16 36B0  2805 3CB8 9250 2FA3 BC2D |



More information about the openssh-unix-dev mailing list