Nasty regreSSHion bug in OpenSSH

Sgarrista
Commissario
Joined
9 Aug 2013
Posts
10,490
Location
Bromsgrove
Nasty indeed.

Fortunately of all my customer servers only a handful needed patching. But those ones were behind IP restricted firewalls.
 
Soldato
Joined
4 May 2003
Posts
3,317
Location
West Oxon, UK
So definitely one to patch but some mitigating factors at least are...
  • There doesn't appear to be a working exploit against a 64bit OS (yet...)
  • Attacker has to know the specific OS that is running
  • Can take up to 8 hours and as many as 10,000 attempts
So unless you're desperately unlucky even a vulnerable version with any kind of reasonable session or rate-limiting in place should offer you fair protection against this
 
Last edited:
Soldato
Joined
14 Jun 2004
Posts
5,653
and all those IOT devices that wont get patched.
Door Access / Building Management System / Cameras / Enviromental monitors / meeting room equipment to name but a few items.
 
Back
Top Bottom