Sunday | 23 November, 2008
How to avoid the Debian SSH key attacks
It only took two days, but viable, simple attacks against the weak Debian SSH key generation flaw have surfaced
Carl Jongsma 16/05/2008 08:35:57

All SSH servers could be affected

There are several ways in which the weak entropy can show itself. One that is causing significant concern from a security point of view is that if a key is generated on a system while it was affected, it will remain weak even after the security fixes have been applied.

People also tend to spread keys around across systems they have access to. This means that if a user creates a key and then installs it on a remote machine, that user's account on that machine is now vulnerable in the same way.

Debian and Ubuntu have now released a blacklist of affected keys which are not allowed to login, and this blacklist is used on up to date Debian and Ubuntu machines. Other systems, such as SUSE, currently do not have a blacklist.

If administrators want to check for weak keys on their system, there is now a script that lets you quickly verify whether some of your keys are vulnerable on the Debian advisory.

Computerworld Buyer's Guide - Vendors Matched to this Article
More about RSA, IPS, SuSE, Ubuntu, Debian, Linux, SSH
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds

Comments

weak security

Every system running an sshd should employ fail2ban, denyhosts, or something similar. Even if it's weakly configured to allow 20 failures or more, there's no reason any ssh server should tolerate a brute force attack of any sort -- ppk, keyboard-interactive, or otherwise.

There are services, such as the DroneBL dnsbl service, that employ honeypot servers to lure attackers onto their blacklist. Adding a line to hosts.deny using aclexec to query such services can improve security. If a host is known to be a source of brute force attacks, it will simply be denied connectivity before any authentication is attempted.

Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Mimosa™ NearPoint™ for Microsoft® Exchange Server: Email Archiving 101

Email archiving is emerging as a critical new application for managing email. Learn how to reduce and manage online and offline email storage, add powerful tools for legal discovery and compliance and extend native exchange recovery capability by reading on.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links