nixCraft ,
@nixCraft@mastodon.social avatar

Heads up: regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server. Patch your server ASAP. https://blog.qualys.com/vulnerabilities-threat-research/2024/07/01/regresshion-remote-unauthenticated-code-execution-vulnerability-in-openssh-server also see my openssh security guide for more info https://www.cyberciti.biz/tips/linux-unix-bsd-openssh-server-best-practices.html

silvenga ,
@silvenga@slvn.social avatar

@nixCraft do we know if fail2ban mitigates this at all (not sure when an open connection is considered and auth failure in the eyes of fail2ban)?

h3artbl33d ,
@h3artbl33d@exquisite.social avatar

@silvenga @nixCraft

It doesn't. Not out of the box with the sshd jail.

farcaller ,
@farcaller@hdev.im avatar

@nixCraft that feel when you no longer have publicly-exposed ssh access. Oh well, now onto the patching.

h3artbl33d ,
@h3artbl33d@exquisite.social avatar

@farcaller @nixCraft

That feel when you run OpenBSD which had it fixed since 2001 :flan_guns:

farcaller ,
@farcaller@hdev.im avatar
  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • test
  • worldmews
  • mews
  • All magazines