- 1
- 2
- < previous
Click here for case studies, whitepapers and other useful vendor content Newsletter Subscription
All SSH servers could be affected
There are several ways in which the weak entropy can show itself. One that is causing significant concern from a security point of view is that if a key is generated on a system while it was affected, it will remain weak even after the security fixes have been applied.
People also tend to spread keys around across systems they have access to. This means that if a user creates a key and then installs it on a remote machine, that user's account on that machine is now vulnerable in the same way.
Debian and Ubuntu have now released a blacklist of affected keys which are not allowed to login, and this blacklist is used on up to date Debian and Ubuntu machines. Other systems, such as SUSE, currently do not have a blacklist.
If administrators want to check for weak keys on their system, there is now a script that lets you quickly verify whether some of your keys are vulnerable on the Debian advisory.
- 1
- 2
- < previous
ARN Member Login
When an IT disaster occurs, how handy it would be to push a button and start again as if nothing had happened.
Discover and learn more about CA XOSoft today.
Tumbleweed appoints O2 Networks to its Australian Channel Partner Program 29 August, 2008 12:31:00
HP ProCurve Brings Big Business Gigabit Switching Features to Small Businesses 29 August, 2008 12:00:00
GlobalConnect Provides Treatment for Healthcare Provider’s Contact Support Requirements 29 August, 2008 09:59:00
Sybase and Logica Partner To Mobilise The Supply Chain 29 August, 2008 09:47:00
New global landscape for qualitative researchers with Spanish and Chinese software releases 29 August, 2008 09:34:00
Microsoft® takes legal action against software pirates
Recently Microsoft took legal action against individuals and resellers for distributing and selling unauthorised Microsoft software.











