SSH flaw puts Unix users on alert

Secure Shell encryption protocol at risk, users warned.

Written by James Middleton

A flaw in SSH Secure Shell protocol has put the Unix community on guard after it emerged that the latest version of the software is vulnerable to attack.

SSH Secure Shell is commonly used in Unix and Linux machines as a method of secure user authentication and data transfer encryption, but version 3.0.0, released late last month, contains a flaw that could give an attacker a foot in the door.

The vulnerability allows a user to remotely log into an account that uses a two-character password, without needing a password at all. Although such instances are uncommon, they happen often enough to pose a threat to a high number of networks.

Even getting into a low-level account could provide a launch pad for a much more serious attack that could potentially result in root access for an attacker.

SSH has issued an advisory and a patch to bring the software up to a secure version 3.0.1. "SSH strongly advises all users of Secure Shell 3.0.0 to upgrade immediately to Secure Shell 3.0.1," said the company.

Along with more information, the patch is available here.

Tags:

Further reading

Puzzling Trojan affects OpenSSH

Geeks in a quandary over mystery infection   More...

Ninja strikes back

Microsoft SQL stalked by Trojan   More...

Sun denies Unix flaw

Vendors alerted while Sun shies away   More...

'Limpninja' Trojan horse emerges

Hackers make ninja-style swoop on Linux boxes   More...

Related articles

'Highly critical' flaws plague Oracle software

Secunia warns of DoS attacks, security bypass and manipulation of data   More...

Apple issues 13 security fixes

Problems with CoreGraphics, Fetchmail, iChat and mDNSResponder   More...

IM flaw hits millions of AOL users

Users exposed to immediate high-risk attacks, warns security firm   More...

New Year resolutions for security managers

Time to push security up the IT agenda   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

16 May 2008

2.97 MBXP on OLPC, broken dreams and Yahoo fights back More...

15 May 2008

3.28 MBDark fibre, mobile TV and solar power More...

14 May 2008

2.66 MBOnline inequality, mobile thumbprints and corporate raids More...

Poll

HOME WORKING

HOME WORKING

Do you let any or all of your employees work from home?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

OLPC

OLPC to ship with Windows XP

Microsoft teams up with One Laptop per Child project   More...

The Sims

The Sims goes flat-pack with Ikea

Virtual world gets Swedish wood   More...

Advertisement

Microsoft-Yahoo

Yahoo board fights back at Icahn

Investor accused of 'significant misunderstanding' in Microsoft saga   More...

MySpace

Woman charged over MySpace suicide

Lori Drew indicted on federal charges   More...

Advertisement