[104976] in Cypherpunks

home help back first fref pref prev next nref lref last post

Re: No vulnerability known in SSH-1.2.26

daemon@ATHENA.MIT.EDU (Anonymous)
Mon Nov 2 21:32:21 1998

Date: Tue, 3 Nov 1998 00:47:24 +0100
From: Anonymous <nobody@replay.com>
To: ylo@ssh.fi, ssh@clinet.fi, coderpunks@toad.com
Reply-To: Anonymous <nobody@replay.com>


Tatu Ylonen wrote:
> We are also trying to track down the linux compilation problem that
> may have caused the false alert behind the IBM advisory.  We will
> issue an announcement as soon as possible if real vulnerability is
> found.

A second possibility, which I obviously can't judge as likely or unlikely
in this case, is that some binary has been intentionally compromised --
adversary gets access for a short time -> bad binaries...time
passes...buffer overflow exploited -> recompilation -> good binaries ->
world-famous disappearing exploit. If the binaries were downloaded, then
we have an entirely different issue to consider (binaries changed at a
source or, less likely, an actual MITM attack).

If you think it's worth checking, just compare hashes of those binaries
(or, if you're ultra-paranoid, actual binaries) which should be identical.

>     Tatu Ylonen <ylo@ssh.fi>

(I won't be able to read replies on ssh)


home help back first fref pref prev next nref lref last post