PhreakPhy
07-09-2009, 01:44 PM
In recent infosec news there has been rumors (http://isc.sans.org/diary.html?storyid=6742)of a supposed SSH 0day exploit. The rumors have not been confirmed with any hard evidence, as such they have been deemed as FUD (http://isc.sans.org/diary.html?storyid=6760).
Prior to the article on SANS at lest one competing web host heard of the forementioned exploit and shut off SSH for all of their shared hosting customers. This was said to have been done to "protect" their customers, but it has been a major inconvenience for the ones that rely on SSH.
Having previously been a customer at bluehost, and now a customer of the host that shut down SSH I happen to have a forum account at both. So I have come here to ask a question of the bluehost community.
What action, if any, has bluehost taken to address the recent supposed SSH 0day exploit?
Prior to the article on SANS at lest one competing web host heard of the forementioned exploit and shut off SSH for all of their shared hosting customers. This was said to have been done to "protect" their customers, but it has been a major inconvenience for the ones that rely on SSH.
Having previously been a customer at bluehost, and now a customer of the host that shut down SSH I happen to have a forum account at both. So I have come here to ask a question of the bluehost community.
What action, if any, has bluehost taken to address the recent supposed SSH 0day exploit?