- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- Open ssh question.
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-23-2003 04:00 AM
09-23-2003 04:00 AM
Open ssh question.
How do i find if i have openssh on a given hp-ux 11 box? Also does anyone know of this alert?
http://www.cert.org/advisories/CA-2003-24.html
Thanks
Brian.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-23-2003 04:25 AM
09-23-2003 04:25 AM
Re: Open ssh question.
They also rolled out their 3.6 binaries with a new version that supposedly plugs the security hole.
Check Berlene Herren's posts for more information.
swlist -l product | grep -i secure
This will list HP Secure Shell, which is what they call their port of openssh.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-23-2003 04:33 AM
09-23-2003 04:33 AM
Re: Open ssh question.
what /usr/bin/ssh
Will give you details on the version you have installed.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-23-2003 04:34 AM
09-23-2003 04:34 AM
Re: Open ssh question.
I use
swlist | grep -i ssh
to check whether it's installed & what ver.
We compile our own SSH here & upgraded to 3.7.1p1 last week as our solution to the CERT advisory.
Rgds,
Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-24-2003 02:04 AM
09-24-2003 02:04 AM
Re: Open ssh question.
Steven Sim Kok Leong
Extract:
===============================================================
[Summary]:
A vulnerability has been discovered in OpenSSH which also affects the recent released versions 3.7p1 and 3.7.1p1. The new version 3.7.1p2 fixes additional relating issues in PAM module, not covered in 3.7.1p1.
[Description]:
A vulnerability was reported in two specific portable versions of OpenSSH in the PAM implementation. A remote user may be able to execute arbitrary code.
It is reported that there are multiple flaws in the new PAM code in portable OpenSSH versions 3.7p1 and 3.7.1p1. In at least one bug, a remote user can cause arbitrary code to be executed on the target system when the targat system is in a non-standard configuration (with privsep disabled).
The vendor notes that the OpenBSD releases of OpenSSH do not contain this code and, therefore, are not vulnerable. Also, portable OpenSSH versions prior to 3.6.1p2 are also not affected.
[Impact]:
A remote user may be able to execute arbitrary code on the target system wtih root privileges.
[Solution]:
The vendor has released a fixed version (3.7.1p2), available at:
http://www.openssh.org/portable.html
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-3.7.1p2.tar.gz
As a workaround, the vendor reports that you can disable PAM support ("UsePam no" in sshd_config).
The vendor has also provided the following warning regarding use of PAM with OpenSSH:
"Due to complexity, inconsistencies in the specification and differences between vendors' PAM implementations we recommend that PAM be left disabled in sshd_config unless there is a need for its use.
Sites only using public key or simple password authentication usually have little need to enable PAM support."
Please note that this version contains the four *realloc() bug fixes that Solar Designer discovered in 3.7.1p1 and prior versions. However, the purpose of the 3.7.1p2 release is to correct the security flaws in the PAM code and not due to the Solar Designer bugs. As described in a previous alert, Solar Designer considers the *realloc() bugs to have no security impact.
[Reference]:
http://www.openssh.com/txt/sshpam.adv
http://isc.sans.org/diary.html?date=2003-09-16
===============================================================
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-24-2003 02:16 AM
09-24-2003 02:16 AM
Re: Open ssh question.
Berlene Herren has a post that indicates that. I'm inclined to trust HP on this one. As they say in my wifes home country, trust but verify.
SEP
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-24-2003 02:37 AM
09-24-2003 02:37 AM
Re: Open ssh question.
Solution:
Upgrade to OpenSSH 3.7.1 or apply the following patch.
Appendix A: patch for OpenSSH 3.6.1 and earlier
From HP security advisory HPSBUX0309-282 :
------------------------------------------
Pursuant to the CERT Advisory CA-2003-24 on OpenSSH, Hewlett-Packard Company has learned of a defect in the code in SSH, product number T1471AA.
HP proposed fix:
------------------
HP has produced the following new depots which fix this defect for its version, which is based on OpenSSH release 3.6.2. Called A.03.61.002, it is the newest version of
HP-UX Secure Shell.
B.11.22 T1471AA_A.03.61.002_HP-UX_B.11.22_IA.depot
B.11.11 T1471AA_A.03.61.002_HP-UX_B.11.11_32+64.depot
B.11.00 T1471AA_A.03.61.002_HP-UX_B.11.00_32+64.depot
------------------
P.S - SEP - I'd say it's more like "Trust but check" from the mentioned (russian?) phrase :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-25-2003 04:06 AM
09-25-2003 04:06 AM
Re: Open ssh question.
Kindly check whether your "trust" is current. As Keev's extract has shown, the HP releases do not fix the latest ssh pam vulnerability.
Refer to:
http://www.openssh.com/txt/sshpam.adv
OpenSSH release version 3.7.1p2 fixes it. Doesn't seem that a HP equivalent patched version is released, yet.
Hope this helps. Regards.
Steven Sim Kok Leong