<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: OpenSSL &amp; OpenSSH Vulnerabilities : Confirm &amp; Fix Instructions</title>
	<atom:link href="http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/feed/" rel="self" type="application/rss+xml" />
	<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/</link>
	<description>Enhancing your Ubuntu experience!</description>
	<lastBuildDate>Fri, 11 May 2012 05:04:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Iñaki Silanes</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-5846</link>
		<dc:creator>Iñaki Silanes</dc:creator>
		<pubDate>Tue, 30 Sep 2008 11:02:48 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-5846</guid>
		<description>Luciano says:

&quot;Hey,
I would like to make you a little but important correction.

&gt; If you do not see “weak key”
&gt; reported then you are OK.’

That’s not totally true. dowkd.pl is really susceptible to have false positives.&quot;

Well, either the message is not correctly phrased, or it is wrong. If dowkd.pl is susceptible to have false positives, it means that it will sometimes have a positive (it will DO say &quot;weak key&quot;), while the key not being really weak (hence, a &quot;false&quot; positive).

What Florian seems to imply is that dowkd.pl has false NEGATIVES: it sometimes says nothing (implying all keys are correct), but this is false (some might be weak).

A positive test is one in which the testing device &quot;ticks&quot;, and a negative one one in which the testing device remaints &quot;silent&quot; (regardless of what ticking or remaining silent imply).</description>
		<content:encoded><![CDATA[<p>Luciano says:</p>
<p>&#8220;Hey,<br />
I would like to make you a little but important correction.</p>
<p>&gt; If you do not see “weak key”<br />
&gt; reported then you are OK.’</p>
<p>That’s not totally true. dowkd.pl is really susceptible to have false positives.&#8221;</p>
<p>Well, either the message is not correctly phrased, or it is wrong. If dowkd.pl is susceptible to have false positives, it means that it will sometimes have a positive (it will DO say &#8220;weak key&#8221;), while the key not being really weak (hence, a &#8220;false&#8221; positive).</p>
<p>What Florian seems to imply is that dowkd.pl has false NEGATIVES: it sometimes says nothing (implying all keys are correct), but this is false (some might be weak).</p>
<p>A positive test is one in which the testing device &#8220;ticks&#8221;, and a negative one one in which the testing device remaints &#8220;silent&#8221; (regardless of what ticking or remaining silent imply).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Projektd</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-5422</link>
		<dc:creator>Projektd</dc:creator>
		<pubDate>Thu, 17 Jul 2008 02:19:05 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-5422</guid>
		<description>Thanks! I needed this. Worked Great.</description>
		<content:encoded><![CDATA[<p>Thanks! I needed this. Worked Great.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gravin</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4588</link>
		<dc:creator>Gravin</dc:creator>
		<pubDate>Tue, 27 May 2008 05:04:37 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4588</guid>
		<description>Thanks!</description>
		<content:encoded><![CDATA[<p>Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Christer Edwards</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4532</link>
		<dc:creator>Christer Edwards</dc:creator>
		<pubDate>Mon, 19 May 2008 23:17:27 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4532</guid>
		<description>@Rafael - you should be seeing a new openssh upgrade soon that will include an openssh blacklist and the new vulnkey tool.  This was not included in the first batch of patches.  My guess is your mirror isn&#039;t up to date just yet.

Also, (see: man ssh-keygen), &quot;DSA keys must be exactly 1024 bits as specified by FIPS 186-2.&quot;, which is why you get that output.</description>
		<content:encoded><![CDATA[<p>@Rafael &#8211; you should be seeing a new openssh upgrade soon that will include an openssh blacklist and the new vulnkey tool.  This was not included in the first batch of patches.  My guess is your mirror isn&#8217;t up to date just yet.</p>
<p>Also, (see: man ssh-keygen), &#8220;DSA keys must be exactly 1024 bits as specified by FIPS 186-2.&#8221;, which is why you get that output.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gecko</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4526</link>
		<dc:creator>Gecko</dc:creator>
		<pubDate>Mon, 19 May 2008 16:07:35 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4526</guid>
		<description>Thank you so much for your help on this.  As a relative newbie, I wasn&#039;t too sure what the heck I was supposed to do other than update in the face of this issue.  Thanks again.</description>
		<content:encoded><![CDATA[<p>Thank you so much for your help on this.  As a relative newbie, I wasn&#8217;t too sure what the heck I was supposed to do other than update in the face of this issue.  Thanks again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rafael</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4523</link>
		<dc:creator>Rafael</dc:creator>
		<pubDate>Mon, 19 May 2008 11:43:16 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4523</guid>
		<description>I have followed all the instructions but I have two problems:

1)I don&#039;t have the tool: ssh-vulnkey

2)When I run ./dowkd.pl host , I get the following error:
server: 2048 bits DSA key not recommended

¿any idea?

Thnks in advance</description>
		<content:encoded><![CDATA[<p>I have followed all the instructions but I have two problems:</p>
<p>1)I don&#8217;t have the tool: ssh-vulnkey</p>
<p>2)When I run ./dowkd.pl host , I get the following error:<br />
server: 2048 bits DSA key not recommended</p>
<p>¿any idea?</p>
<p>Thnks in advance</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Thomas</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4504</link>
		<dc:creator>Thomas</dc:creator>
		<pubDate>Fri, 16 May 2008 06:10:17 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4504</guid>
		<description>Oh the irony, a fix for a security vulnerability that downloads a script using HTTP and then runs it...

Download the signature too, then verify it!

wget http://security..../dowkd.pl.gz.asc
gpg dowkd.pl.gz.asc

You&#039;ll probably get a &#039;key not found&#039; error. Import the key (it&#039;ll tell you the RSA key ID):

gpg --recv-keys 02D524BE

Now when you run it again. It should tell you that the signature matches, but that the key is untrusted.

Now the real fun begins :-)

You need to verify the key signature, then you need to decide if you actually trust this &quot;Florian Weimer&quot; guy, and _THEN_ you can run the script!
(I can tell you, but that&#039;d be pointless &#039;cos then you&#039;d have to decide whether or not you trust me :-)

Security is NOT easy, but failing to do the above means that you&#039;re on par with the guy who runs &quot;WindowsSecurityPatch.exe&quot; attachments he gets in the mail.</description>
		<content:encoded><![CDATA[<p>Oh the irony, a fix for a security vulnerability that downloads a script using HTTP and then runs it&#8230;</p>
<p>Download the signature too, then verify it!</p>
<p>wget <a href="http://security" rel="nofollow">http://security</a>&#8230;./dowkd.pl.gz.asc<br />
gpg dowkd.pl.gz.asc</p>
<p>You&#8217;ll probably get a &#8216;key not found&#8217; error. Import the key (it&#8217;ll tell you the RSA key ID):</p>
<p>gpg &#8211;recv-keys 02D524BE</p>
<p>Now when you run it again. It should tell you that the signature matches, but that the key is untrusted.</p>
<p>Now the real fun begins <img src='http://ubuntu-tutorials.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>You need to verify the key signature, then you need to decide if you actually trust this &#8220;Florian Weimer&#8221; guy, and _THEN_ you can run the script!<br />
(I can tell you, but that&#8217;d be pointless &#8216;cos then you&#8217;d have to decide whether or not you trust me <img src='http://ubuntu-tutorials.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Security is NOT easy, but failing to do the above means that you&#8217;re on par with the guy who runs &#8220;WindowsSecurityPatch.exe&#8221; attachments he gets in the mail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Yazz D. Atlas</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4498</link>
		<dc:creator>Yazz D. Atlas</dc:creator>
		<pubDate>Thu, 15 May 2008 18:28:08 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4498</guid>
		<description>!/bin/bash
wget http://security.debian.org/project/extra/dowkd/dowkd.pl.gz &amp;&amp; \
gzip -d dowkd.pl.gz &amp;&amp; \
for i in $(/bin/ls -1 /home ); do perl dowkd.pl user $i; done &amp;&amp; \
for i in $(/bin/ls -1 /etc/ssh/*.pub) ; do perl dowkd.pl file $i; done</description>
		<content:encoded><![CDATA[<p>!/bin/bash<br />
wget <a href="http://security.debian.org/project/extra/dowkd/dowkd.pl.gz" rel="nofollow">http://security.debian.org/project/extra/dowkd/dowkd.pl.gz</a> &amp;&amp; \<br />
gzip -d dowkd.pl.gz &amp;&amp; \<br />
for i in $(/bin/ls -1 /home ); do perl dowkd.pl user $i; done &amp;&amp; \<br />
for i in $(/bin/ls -1 /etc/ssh/*.pub) ; do perl dowkd.pl file $i; done</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nick M</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4485</link>
		<dc:creator>Nick M</dc:creator>
		<pubDate>Wed, 14 May 2008 20:12:45 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4485</guid>
		<description>Wow, thanks! I think I just found my new favorite Ubuntu site!  :)</description>
		<content:encoded><![CDATA[<p>Wow, thanks! I think I just found my new favorite Ubuntu site!  <img src='http://ubuntu-tutorials.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Manfred</title>
		<link>http://ubuntu-tutorials.com/2008/05/13/openssh-openssh-vulnerabilities-confirm-fix-instructions/#comment-4483</link>
		<dc:creator>Manfred</dc:creator>
		<pubDate>Wed, 14 May 2008 14:40:08 +0000</pubDate>
		<guid isPermaLink="false">http://ubuntu-tutorials.com/?p=639#comment-4483</guid>
		<description>When I tried your script I got the following message:

./dowkd.pl user
/home/jonny/.ssh/authorized_keys:1: warning: unparsable line

Is that indicating a problem?</description>
		<content:encoded><![CDATA[<p>When I tried your script I got the following message:</p>
<p>./dowkd.pl user<br />
/home/jonny/.ssh/authorized_keys:1: warning: unparsable line</p>
<p>Is that indicating a problem?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: basic (User agent is rejected)
Database Caching 2/5 queries in 0.003 seconds using disk: basic
Object Caching 327/327 objects using disk: basic

Served from: ubuntu-tutorials.com @ 2012-05-24 22:06:37 -->
