3 month ago
nelson : Debian/OpenSSL analysis - A very detailed examination of how the bug happened
# copy
3 month ago
nelson : ssh brute force attacks on the upswing - A few days before the Debian disclosure there was a significant increase in attacks on ssh servers. That is bad news.
# copy
4 month ago
nelson : Dealing with Debian's ssh vulnerability - For two years the ssh keys generated by Debian have been broken.
# copy
4 month ago
mmb : Debian OpenSSL Predictable PRNG Toys - Debian OpenSSL Predictable PRNG Toys via Popular pages on del.icio.us [via]
nelson : Debian ssh exploit - Someone published a list of all possible Debian ssh keys. In case you weren't sure the bug was serious.
Rod Begbie : Debian OpenSSL Predictable PRNG Toys - More details on the Debian openssl patch farrago. Important point: Every sysadmin needs to scan their boxes (not just Debian users) to find any compromisable .authorized_keys [via] #
# copy19 month ago
nelson : Debian, dovecot, SSL - Sure is a lot easier than trying to understand how to generate certificates by hand
# copy
19 month ago
nelson : OpenSSL cheatsheet - Decoder ring for yet another mysterious Unix command line tool
# copy