PDA

View Full Version : Supposed SSH 0day exploit



PhreakPhy
07-09-2009, 01:44 PM
In recent infosec news there has been rumors (http://isc.sans.org/diary.html?storyid=6742)of a supposed SSH 0day exploit. The rumors have not been confirmed with any hard evidence, as such they have been deemed as FUD (http://isc.sans.org/diary.html?storyid=6760).

Prior to the article on SANS at lest one competing web host heard of the forementioned exploit and shut off SSH for all of their shared hosting customers. This was said to have been done to "protect" their customers, but it has been a major inconvenience for the ones that rely on SSH.

Having previously been a customer at bluehost, and now a customer of the host that shut down SSH I happen to have a forum account at both. So I have come here to ask a question of the bluehost community.

What action, if any, has bluehost taken to address the recent supposed SSH 0day exploit?

Early Out
07-09-2009, 01:45 PM
Haven't heard anything about it.

felgall
07-09-2009, 02:55 PM
I haven't heard anything about it anywhere (and I regularly visit several forums where such things would get mentioned if there was any truth to it).

PhreakPhy
07-09-2009, 03:26 PM
I would call the SANS Internet Storm Center a credible source for information security news. The rumor spread quickly over the internet since so many people have a lot at stake in the event of an OpenSSH vulnerability. Frankly, I am surprised no one here has heard of it.

Early Out
07-09-2009, 03:30 PM
I would call the SANS Internet Storm Center a credible source for information security news.
Yes, but they're still calling it merely a rumor, not something that they have any concrete evidence about.

PhreakPhy
07-10-2009, 08:43 AM
Yes, but for some reason my current host still seems to be limiting SSH by IP address, and has otherwise locked it down.
Lame.