Re: Firewall your ssh status port
Jan Willamowius <[email protected]> Tue, 7 Feb 2017 09:30:14 +0100
| Newsgroups | gmane.comp.telephony.openh323gk.user |
|---|---|
| Organization | GNU Gatekeeper Project |
| Message-ID | <[email protected]> |
I think I still owe you the details on this one: All GnuGk versions prior to 4.4 can be crashed by remotely opening and closing multiple ssh connections to the status port (even without having the ssh credentials). As far as I can tell, this "only" results in a denial of service and no remote code execution is possible. So, if you use ssh on the status port, please make sure to update to GnuGk to 4.4. Regards, Jan -- = Jan Willamowius, Founder of the GNU Gatekeeper Project EMail : [email protected] Website: https://www.gnugk.org Support: https://www.willamowius.com/gnugk-support.html Relaxed Communications GmbH Frahmredder 91 22393 Hamburg Gesch=E4ftsf=FChrer: Jan Willamowius HRB 125261 (Amtsgericht Hamburg) USt-IdNr: DE286003584 Jan Willamowius wrote: > Hi, > = > users who have enabled ssh on the status port should block access to > the status port in their firewall or upgrade to the CVS version as soon > as possible. > = > More details later. > = > Regards, > Jan ---------------------------------------------------------------------------= --- Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot _______________________________________________________ Posting: mailto:[email protected] Archive: http://sourceforge.net/mailarchive/forum.php?forum_name=3Dopenh323= gk-users Unsubscribe: http://lists.sourceforge.net/lists/listinfo/openh323gk-users Homepage: http://www.gnugk.org/