Bugtraq mailing list archives
Re: SSH 1.x and 2.x Daemon
From: linux () AIIND UPV ES (Linux Mailing Lists)
Date: Mon, 25 Jan 1999 20:40:09 +0100
Hello,
There seems to be incomplete code in the SSH daemon in both versions 1.2.27 and 2.0.11 (only tested). The bug simply allows users who with expired accounts (in /etc/shadow) to continue to login even though other such services such as ftp and telnet deny access. Here is the log using 1.2.27 (but the same happens with 2.0.11).This is not the case with ssh 1.1.26 running on FreeBSD 2.2.8 If I expire an account: Expire [month day year]: January 1, 1999 Then when I try to ssh in I just get: Permission denied.
There's a configure parameter to use the "usual" /bin/login program instead of the login procedure implemented with ssh: --with-login[=PATH] Use login -f to finish login connections. On one hand, a possible fix (temporal, of course) is to compile sshd with support for /bin/login. The features of the shadow-suite will be back. On the other hand, SSH 1.2.26 seems to implement the expiration date of accounts (grep expire sshd.c), but I don't know if it does it ok. Greetings, Sergio
Current thread:
- Re: WebRamp M3 remote network access bug, (continued)
- Re: WebRamp M3 remote network access bug James Egelhof (Jan 21)
- Perl.exe and IIS security advisory mnemonix (Jan 22)
- Re: Perl.exe and IIS security advisory Tabor J. Wells (Jan 24)
- Repost: Wietse's FTP site has moved Wietse Venema (Jan 25)
- Using Example Domain Names in Exploits bandregg () REDHAT COM (Jan 25)
- IIS Advisory Update Marc (Jan 24)
- backdoored tcp wrapper source code Wietse Venema (Jan 21)
- Re: backdoored tcp wrapper source code John Stange (Jan 23)
- SSH 1.x and 2.x Daemon KuRuPTioN (Jan 23)
- Re: SSH 1.x and 2.x Daemon Jan B. Koum (Jan 24)
- Re: SSH 1.x and 2.x Daemon Linux Mailing Lists (Jan 25)
- Re: SSH 1.x and 2.x Daemon KuRuPTioN (Jan 25)
- Re: backdoored tcp wrapper source code John Stange (Jan 23)
- Re: SSH 1.x and 2.x Daemon Alan Olsen (Jan 24)
- baynetworks router DoS Virsoft (Jan 25)
- Re: baynetworks router DoS Neale Banks (Jan 26)
- 2.2.0 SECURITY (fwd) Aaron Lehmann (Jan 26)
- IBM CICS Universal Client 3.x Rude Yak (Jan 27)
- Re: SSH 1.x and 2.x Daemon Yutaka OIWA (Jan 25)
- Call for Papers: UNIX AND WINDOWS NT Fred Donck (Jan 25)
- New IE4 privacy issue aleph1 () UNDERGROUND ORG (Jan 25)
- Re: SSH 1.x and 2.x Daemon Jim Bourne (Jan 25)