OpenSSH Vulnerability Discovered 116
farker haiku writes "Those of you who haven't heard of the metasploit project, it's an open source product for performing security audits. This time they've managed to find a remote buffer overflow in OpenSSH. Ya'll might want to read the link and then do whatever updating is necessary." It's unfortunate that something like this gets released today since nobody will bother to patch.
Beer sploit confirmed! (Score:5, Funny)
My stomach had a couple of buffer overflows last-night. It was sploited by Arthur Guinness, well known for his ingenious bowel movement exploits.
It may take a life time to fix this vulnerability :(
Simon
Re:Beer sploit confirmed! (Score:1)
Re:Beer sploit confirmed! (Score:5, Funny)
Re:Beer sploit confirmed! (Score:1)
Re:Beer sploit confirmed! (Score:2)
Re:Beer sploit confirmed! (Score:1)
Re:Beer sploit confirmed! (Score:3, Insightful)
Re:Beer sploit confirmed! (Score:1)
Oh yeah, because there's never been a serious, pre-authentication remote root in OpenSSH. And thousands of people didn't get hacked by it.
It's in the Matrix movie for fucks sake. And what do you think was the cause of that "One remote hole in the default install in 8 years" on the OpenBSD site? Yes, well done - OpenSSH.
I don't care! Exploit me! (Score:3, Funny)
Beersploit (Score:1)
then again I might not care about much at all at that point
Cheers!
Kilobeer (Score:2, Funny)
Re:Follow the standards!!! (Score:2, Insightful)
Re:Follow the standards!!! (Score:2)
Re:Follow the standards!!! (Score:2)
You may not like the "mebibyte" and "gibibyte" names, but you've got to admit that the whole thing is a mess and something needs to be done to resolve the confusion.
Re:Follow the standards!!! (Score:1)
So, for all traditional physical units:
k : base = 10 , exponent = 3, M: base = 10, exponent = 6, etc
For bits and bytes etc:
k: base = 2, exponent = 10, M: base = 2, exponent = 20, etc
Simple. No bibology or kibology or any other sillyness needed.
-Lasse
Re:Follow the standards!!! (Score:2)
Simple"
It migth be not so simple when even the proponent (aka "you") isn't able to apropiately manage the numbers, don't you think so?
How the heck can you use an "exponent 20" when you are working base2? Remember, within base2, the number 2 is the forbidden one: only ones and zeroes allowed.
Re:Follow the standards!!! (Score:1)
Using your logic, everything is base 10, because whenever the word base is used, noone expects decimal numbers, right?
-Lasse
"Always be ready to speak your mind and a base man will avoid you." (William Blake)
Re:Kilobeer (Score:1)
#include (Score:2, Funny)
Re:#include (Score:2)
Anyway. My guess is that the fast workaround for this problem is to limit the MAX_BEERS #define to a sensible value of 0x100 or 0x200 'til the problem is fixed.
Re:#include (Score:1)
Anyway, the alcohol.h library is completely insecure and buggy. It causes my terminal to spit out it's core and terminate.
Re:#include (Score:2)
Re:#include (Score:1)
Then set the limit of MAX_BEERS to a sensible value for a real Irish person of 0x999999999999
Re:#include (Score:1)
Insert Typical Slashbot April Fools Complaint (Score:5, Funny)
----
-Signiture as unamusing as the current slashdot story.
Re:Insert Typical Slashbot April Fools Complaint (Score:5, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:5, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:3, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:2)
<Donut[AFK]> INSULT
<Eurakarte> RETORT
<Donut[AFK]> COUNTER-RETORT
<Eurakarte> QUESTIONING OF SEXUAL PREFERENCE
<Donut[AFK]> SUGGESTION TO SHUT THE FUCK UP
<Eurakarte> NOTATION THAT YOU CREATE A VACUUM
<Donut[AFK]> RIPOSTE
<Donut[AFK]> ADDON RIPOSTE
<Eurakarte> COUNTER-RIPOSTE
<Donut[AFK]> COUNTER-COUNTER RIPOSTE
<Eurakarte> NONSENSICAL STATEMENT INVOLVING PLANKTON
<Miles_Prower> RESPONSE TO RANDOM STATEMENT AND THR
Re:Insert Typical Slashbot April Fools Complaint (Score:2, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:3, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:3, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:3, Funny)
Re:Insert Typical Slashbot April Fools Complaint (Score:2)
Re:Insert Typical Slashbot April Fools Complaint (Score:1)
Re:It's a dirty job but someone has to do it... (Score:2)
Request to Moderators (Score:1)
Annoying reactionary flame (Score:5, Funny)
Re:Annoying reactionary flame (Score:2, Funny)
Re:Annoying reactionary flame (Score:5, Funny)
Self-congratulatory explanation of logical fallacies of above argument. Arrogant insinuation that I am smarter than you. More big words, many in italicized non-English, attempting to display my advanced education.
Re:Annoying reactionary flame (Score:3, Funny)
Re:Annoying reactionary flame (Score:3)
Re:Annoying reactionary flame (Score:4, Funny)
Schizophrenic adoration and condemnation of Bush over stem cell policies[1] and their impact on cancer cures.
Personal vow to give up
[1] Meaningless footnote to supply veneer of academic rigor.
Re:Annoying reactionary flame (Score:1)
Re:Insert Typical Slashbot April Fools Complaint (Score:3, Insightful)
Once the 1st was over they could then return to their usual methods.
Just think of all the people that avoid the site during this time because of the way it operates during this time period.
Re:Insert Typical Slashbot April Fools Complaint (Score:1)
Re:Insert Typical Slashbot April Fools Complaint (Score:1)
Re:Insert Typical Slashbot April Fools Complaint (Score:2)
Re:Insert Typical Slashbot April Fools Complaint (Score:2)
Re:Insert Typical Slashbot April Fools Complaint (Score:1)
OpenSSH hacked, Theo deRaadt kicked out (Score:1)
Re:OpenSSH hacked, Theo deRaadt kicked out (Score:2)
O, the dead rat!
Nice (Score:2)
Somebody used this to hack the slashdot.jp page (Score:2, Funny)
--
me spell? me not even now eigo.
Hey the spirit is still there. (Score:2)
Guess what two of the posts say. April fool. No. I don't read Japanese. The only words in English on that website is April fool.
Re:Hey the spirit is still there. (Score:2)
Re:Hey the spirit is still there. (Score:1)
Enough already! (Score:4, Funny)
The really unfunny thing is that this is _so_ obviously an April
Fools joke, that's it's not even remotely funny. At least the "UK
Government shutting down GSM" was a plausible story, but this...
Sheesh!
Re:Enough already! (Score:2)
LINUX DEVELOPERS!!!! LOOK WHAT YOU HAVE DONE!!! (Score:1, Funny)
Re:This is not funny... (Score:1)
-Lasse
APRIL FOOLS!! (Score:4, Funny)
NO CARRIER
Sun Microsystems (Score:1)
Sites that don't do 4/1? (Score:1, Insightful)
On behalf of the huge number of us who chuckled after the first couple of stories and now want to vomit and find another temporary news site for today...Please, for the love of god, make an option on the front page so you can turn off the April Fools stories and actually get real news. You are a news site, and while it is great to take part in this holiday and have some laughs, there's still plenty of actual news occuring and it pisses a great many of us off that we now have to go to alternate sources
Re:Sites that don't do 4/1? (Score:1)
Re:Sites that don't do 4/1? (Score:2, Funny)
Bemopolis
Re:Sites that don't do 4/1? (Score:1)
Bemopolis
Re:Sites that don't do 4/1? (Score:2)
Re:Sites that don't do 4/1? (Score:2)
Re:Sites that don't do 4/1? (Score:1)
Good luck with that.
dangerous (Score:2, Insightful)
I must admit from reading the title my heart missed a beat. Theres's gotta be something real on 1.april, no ?
Workaround (Score:4, Funny)
iptables -I INPUT 1 -mlength --length 0:1024 --protocol beer -j DONTPAY
Re:Workaround (Score:1)
iptables -I INPUT 1 -mlength --length 1025:1000000 --protocol beer -j GETCOFFEE
It works for me.
And in other news (Score:2)
Re:And in other news (Score:2)
Attention Grammar Police! (Score:2)
3. Theo enjoys the monk's very good beer
Re:Attention Grammar Police! (Score:2)
3. Theo enjoys the monks' very good beer
Re:Attention Grammar Police! (Score:2)
Re:Attention Grammar Police! (Score:2)
Re:And in other news (Score:2)
April 1st (Score:2)
Re:April 1st (Score:1)
Re:April 1st (Score:1)
Re:April 1st (Score:2)
APRIL FOOLS! (Score:1)
Actually not bad. (Score:2)
fools (Score:2)