4 msgRe: Accepted openssh-blacklist 0.3 (source all)
4 msgRE: [SECURITY] [DSA 1583-1] New gnome-peercast ...
17 msgopenssh remote upgrade procedure?
3 msgopenssh lockup after blacklist hits
1 msgRE: [SECURITY] [DSA 1576-2] New openssh package...
3 msgrealpath in PS1 bash
22 msgopenssl-blacklist & two keys per one pid
2 msgDebian OpenSSL Weak Key Detector (dowkd) versio...
1 msgFranz Tischler ist außer Haus.
9 msgdowkd.pl false positives
3 msgSASL AUTH only check 8 first characters of the ...
1 msgMinor improvement to openssl-blacklist
3 msgFault in openssl-blacklist - version 0.1 -- fal...
10 msgThanks to Debian OpenSSL developers
1 msgpr1
6 msgRe: blacklist.RSA-1024 missing?
1 msgopenssh: working exploit on bugtraq
6 msgDSA-1571 and GSSAPI

ssh-vulnkey and authorized_keys
\ Vladislav Kurz (15 May 2008)
. \ Mikko Rapeli (15 May 2008)
. . \ Noah Meyerhans (15 May 2008)
. . . \ CaT (17 May 2008)
. \ Alex Samad (15 May 2008)
. . \ Chris Adams (16 May 2008)
. . . \ Felipe Augusto van de Wiel (faw) (16 May 2008)
. . . . \ Alberto Gonzalez Iniesta (16 May 2008)
. . . . \ Kees Cook (16 May 2008)
. . . . . \ Felipe Augusto van de Wiel (faw) (16 May 2008)
. . . \ Alex Samad (16 May 2008)
. . . . \ James Miller (19 May 2008)
. . . . . \ Florian Weimer (19 May 2008)

5 msgRe: [SECURITY] [DSA 1571-1] vulnerability of pa...
Subject:ssh-vulnkey and authorized_keys
Group:Debian-security
From:Vladislav Kurz
Date:15 May 2008


 

Hello all,

thanks for the quick response to the SSL bug and for providing ssh-vulnkey and
dokuwd.pl. SSH-VULNKEY produces funny output when processing authorized_keys
with additional options like from="host", command="something to do",
no-agent-forwarding, etc...

Instead of the file name it prints these extra options. It is hard to find
such files then, especialy if they are not in regular user homes but used for
special purposes (backups, monitoring) and located on unusual places.

It would be also helpful to print the line as dokuwd.pl does.
Is there any repository with newer versions of ssh-vulnkey or dokuwd.pl ?

--
Regards
Vladislav Kurz


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com