Does anybody know if the openSSH exploit is applicable to Mac OS X?
and if so how does one apply the information shown here?
http://www.openssh.com/txt/buffer.adv
<http://docs.info.apple.com/article.html?artnum=106274>
states openSSH is used in OS X
http://docs.info.apple.com/article.html?artnum=61798
indicates an openSSH exploit patch that came out a year ago
need to know as I have two network admins giving me heat about slow
patch releases... actually as I don't enable file/web/terminal etc
sharing and turn on the firewall software when setting up users
computers the issue is possibly not quite so urgent as they are
making it out to be.
You could either wait for the Apple software update, or attempt to
install OpenSSH 3.7.1 yourself (although I note that someone's just
reported even more vulnerabilities that may need to be patched).
Note that:
* If you haven't enabled remote login, it's not a problem, and by
default Mac OS X doesn't have this enabled (but I believe Mac OS X
server does)
* Exploits that work on Intel processors don't necessarily work on
PowerPC based machines as the buffer has to be overrun with different
code.
For the moment just to be paranoid I've created an /etc/hosts.allow
and /etc/hosts.deny and locked all my services down to known IP
numbers. This is of course a pain if you or your users are on the
road.
Have fun,
Shay
--
=========================== Shay Telfer ================================
Perth, Western Australia Technomancer Join Team Sungroper, race the
Opinions for hire [POQ] 2003 World Solar Challenge
[EMAIL PROTECTED] fnord <http://sungroper.asn.au/>