OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: OpenSSH heads-up

From: Eli Dart (dartnersc.gov)
Date: Tue Sep 16 2003 - 14:25:23 CDT


In reply to Brett Glass <brettlariat.org> :

> At 07:43 AM 9/16/2003, Jacques A. Vidrine wrote:
>

> Could it be that some party or parties knew about this before the announcement
> and is probing for hosts to exploit?

I always assume that the blackhats are at least 6 to 12 months ahead
of public disclosure....

The kiddies may not have as much of a lead, depending on how good
their sources for exploit code are, but one should assume that
Smart Bad People can own one's machines if one's only defense is a
current patch set.

                --eli

>
> --Brett Glass
>
>
>
> _______________________________________________
> freebsd-securityfreebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-security
> To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (FreeBSD)
Comment: Exmh version 2.5 07/13/2001

iD8DBQE/Z2OjLTFEeF+CsrMRAinEAJ0XRjXxvKgIP6g86MsC4XvJQJ5OOgCgni/a
Sq+D56RaPe+kVu45YRC38B8=
=s+Nj
-----END PGP SIGNATURE-----