[Security Advisories]OpenSSH Uselogin and PermitRootLogin



贊助商連結


repsol
2002-02-02, 01:42 AM
可能有點舊了 ...不過還是提一下好了...


OpenSSH is an implementation of the Secure Shell protocol. When OpenSSH is configured with the UseLogin directive equal to "yes", an intruder can execute arbitrary code with the privileges of OpenSSH, usually root.


修正sshd_config


UseLogin no
PermitRootLogin no


重新起動sshd



ps : 最新版OpenSSH 為 openssh-3.0.2p1