CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

Debian OpenSSL vuln/update

 
Post new topic   Reply to topic       All -> FavForums -> LinuxOS [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4637
Location: USA

PostPosted: Wed May 14, 2008 9:37 pm    Post subject: Debian OpenSSL vuln/update
Reply with quote

FYI...

- http://www.theregister.co.uk/2008/05/13/debian_openssl_bug/
13 May 2008 - "Debian has warned of a vulnerability in its cryptographic functions that could leave systems open to attack. The use of a cryptographically flawed pseudo random number generator in Debian's implementation of OpenSSL meant that potentially predictable keys were generated. Versions of Debian's OpenSSL packages starting with 0.9.8c-1 (released in September 2006) are potentially vulnerable...

- http://secunia.com/advisories/30220/
Release Date: 2008-05-13
Critical: Highly critical
Impact: Security Bypass, DoS, System access
Where: From remote
Solution Status: Vendor Patch
...The security issue is reported in Debian's OpenSSL packages starting with 0.9.8c-1... affects all keys generated with an affected package...
Original Advisory:
http://lists.debian.org/debian-security-announce/2008/msg00152.html

Shocked


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4637
Location: USA

PostPosted: Thu May 15, 2008 9:49 am    Post subject:
Reply with quote

FYI...

- http://isc.sans.org/diary.html?storyid=4420
Last Updated: 2008-05-15 07:47:03 UTC - "...H D Moore posted a web page containing all SSH 1024, 2048 and 4096-bit RSA keys he brute forced. It is obvious that this is highly critical – if you are running a Debian or Ubuntu system, and you are using keys for SSH authentication (ironically, that's something we've been recommending for a long time), and those keys were generated between September 2006 and May 13th 2008 then you are vulnerable. In other words, those secure systems can be very easily brute forced. What's even worse, H D Moore said that he will soon release a brute force tool that will allow an attacker easy access to any SSH account that uses public key authentication. But this is not all – keep in mind that ANY cryptographic material created on vulnerable systems can be compromised. If you generated SSL keys on such Debian or Ubuntu systems, you will have to recreate the certificates and get them signed again. An attacker can even decrypt old SSH sessions now. The Debian project guys released a tool that can detect weak keys (it is not 100% correct though as the blacklist in the tool can be incomplete). You can download the tool from http://security.debian.org/project/extra/dowkd/dowkd.pl.gz ...Please check your systems and make sure that you are both patched, and that you regenerated any potentially weak cryptographic material."

Shocked


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4637
Location: USA

PostPosted: Fri May 16, 2008 4:20 pm    Post subject:
Reply with quote

- http://isc.sans.org/diary.html?storyid=4421
Last Updated: 2008-05-15 23:16:38 UTC ...(Version: 3)

- http://www.us-cert.gov/current/#debian_openssl_vulnerability
May 15, 2008

Threatcon - Symantec
- http://www.symantec.com/security_response/threatconlearn.jsp
2008-05-16 05:28 - "ThreatCon is currently at Level 2: Elevated.
The ThreatCon is at level 2. Advisories have been released addressing an issue related to weak key generation in Debian and its variants, such as Ubuntu. Using a weak random number generator in the OpenSSL package, the system generates a weak key when installing services such as Secure Shell (SSH) and OpenVPN. To fix this issue, users are advised to apply available updates for the OpenSSL library and to regenerate all cryptographic keys generated previously by the library. Keys generated from GNUPG and GNUTLS packages are reportedly unaffected. Several tools are already available that allow a brute-force attack against the weak keys. H D Moore has released a database of all weak keys generated for a typical encryption key space:
( http://metasploit.com/users/hdm/tools/debian-openssl/ )
A script to brute-force the keys using that database has also been released on milw0rm by M. Mueller:
( http://www.milw0rm.com/exploits/5622 )
These tools could be used to bypass key-based login for shell services such as SSH. Other potential tools could be used to decrypt traffic such as login information or to forge digital signatures.
The Debian advisory addressing the issue provides information on how to tell if your system was using vulnerable keys. The following Debian and Ubuntu advisories are available:
DSA-1571-1 openssl -- predictable random number generator
( http://www.debian.org/security/2008/dsa-1571 )
USN-612-1: OpenSSL vulnerability
( http://www.ubuntu.com/usn/USN-612-1 ) ."

-----------


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
AplusWebMaster

General
General


Joined: Mar 14, 2004
Posts: 4637
Location: USA

PostPosted: Sun May 18, 2008 12:33 pm    Post subject:
Reply with quote

FYI...

- http://isc.sans.org/diary.html?storyid=4423
Last Updated: 2008-05-16 21:56:23 UTC - "...Debian Wiki has a good (and evolving) write-up on problems and resolutions: wiki.debian.org/SSLkeys* ... check those "authorized_keys" files for SSH on -all- platforms, not just on Debian."
* http://wiki.debian.org/SSLkeys

Exclamation


_________________
AplusWebMaster
~ Are you up to date or vulnerable to Hackers? ...or both?
.
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> LinuxOS All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer