[Tfug] Debian SSH vulnerability

Tom Rini trini at kernel.crashing.org
Tue May 13 13:11:52 MST 2008


On Tue, May 13, 2008 at 12:52:06PM -0700, Claude Rubinson wrote:

> Debian Users - it's time to regenerate our SSH keys.  Turns out that
> Debian's random number generator isn't.  See
> http://lists.debian.org/debian-security-announce/2008/msg00152.html

This made me go and see just how many old and useless (as I don't think
most of those machines exist anywhere anymore) SSHv1 keys I still had
around.  Perhaps this also explains the rash of ssh logins I've been
seeing the past few days...

-- 
Tom Rini




More information about the tfug mailing list