Re: SSH on Solaris

From: Chris Thompson (cet1_at_cus.cam.ac.uk)
Date: 09/17/03


Date: 17 Sep 2003 20:53:52 GMT

In article <pan.2003.09.17.18.30.02.556627@uiuc.edu>,
Patrick Zurek <pzurek@uiuc.edu> wrote:
>On Wed, 17 Sep 2003 11:36:51 -0500, Chris Cox wrote:
>
>> Baby Peanut wrote:
>>> Great, really great. Now there's no word from Sun about a patch for
>>> their SSH and SunFreeWare has no OpenSSH 3.7p1 offerings.
>>>
>>> Sun Security? Your on your own.
>>>
>>> P.S. I do know how to make my own Solaris packages, it's just a PITA.
>>
>> Btw, there are exploits in the wild already and our servers are
>> getting hit... good idea to block outside access until you can
>> get a patch ready.
>
>I was told by my supervisor who spent the last couple of days researching
>this that Sun's SSH package wasn't vulnerable to this latest OpenSSH
>vulnerability.

S/he's got access to the source code for Sun SSH?

> I do realize SunSSH is based on OpenSSH.

But diverged from it quite a way back now, it seems.

It's a pity that OpenSSH isn't GPL'd, as then Sun would have to (IANAL)
make their source available.

Chris Thompson
Email: cet1 [at] cam.ac.uk



Relevant Pages

  • CERT Advisory CA-2002-24 Trojan Horse OpenSSH Distribution (fwd)
    ... CERT Advisory CA-2002-24 Trojan Horse OpenSSH Distribution ... version of the source code. ...
    (FreeBSD-Security)
  • Re: OpenSSH on windows Problem
    ... I have been working on a similar project, MPlayer on Windows so I can answer ... cygwin1.dll and several other dlls. ... openssh .exe files to another computer and try to run them. ... > now) do i have to open my source code. ...
    (SSH)
  • SUMMARY: Sun SSH vs OpenSSH
    ... Whenever the alert ... understanding is that Sun SSH is based upon a version of OpenSSH. ... security issues with the ssh protocol, use OpenSSH and not Sun SSH? ... Any vulnerability in OpenSSH is evaluated by Sun, ...
    (SunManagers)
  • Re: get child pids from parent pid ?
    ... there is likely no suitable solution to such an ill-defined problem. ... If the OP is trying to send SIGUSR1 to OpenSSH processes, ... altered the source code. ...
    (comp.unix.programmer)
  • algorithm plugins
    ... Compression alg) using OpenSSH, ... Hack the source code and insert appropriate library functions, ...
    (comp.security.ssh)