OpenSSH Trojan Horse Vulnerability
BID:5374
Info
OpenSSH Trojan Horse Vulnerability
| Bugtraq ID: | 5374 |
| Class: | Unknown |
| CVE: |
CVE-1999-0661 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 01 2002 12:00AM |
| Updated: | Jul 11 2009 02:56PM |
| Credit: | The discoverer of this issue is not currently known at this time. |
| Vulnerable: |
OpenSSH OpenSSH 3.4 p1 OpenSSH OpenSSH 3.4 OpenSSH OpenSSH 3.2.2 p1 |
| Not Vulnerable: | |
Discussion
OpenSSH Trojan Horse Vulnerability
Reportedly, the server hosting openssh, ftp.openbsd.org, was compromised recently. It has been reported that the intruder made modifications to the source code of openssh to include trojan horse code. Downloads of the openssh source code from ftp.openbsd.org between July 30, 2002 and July 31, 2002 likely contain the trojan code.
The trojan code appears to be included in the file, bf-test.c. Reports say that the trojan will run once upon compilation of openssh. The trojan process is named 'sh' or the compiling user's default shell. Once executed the trojan attempts to connect to 203.62.158.32 on port 6667. The trojan will then wait for one of three commands.
The following sites also have been reported to carry the trojaned version of openssh-3.4p1.tar.gz:
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/
ftp://ftp.usa.openbsd.org/pub/OpenBSD/OpenSSH/
ftp://ftp1.se.openbsd.org/pub/OpenBSD/OpenSSH/
It is not known whether other sites are affected as well.
*** The OpenSSH team has released an advisory. Fixed versions of openssh are available for download since 1300 UTC August 1, 2002. The following MD5 checksum information was provided for fixed versions of openssh:
MD5 (openssh-3.4p1.tar.gz) = 459c1d0262e939d6432f193c7a4ba8a8
MD5 (openssh-3.4p1.tar.gz.sig) = d5a956263287e7fd261528bb1962f24c
MD5 (openssh-3.4.tgz) = 39659226ff5b0d16d0290b21f67c46f2
MD5 (openssh-3.2.2p1.tar.gz) = 9d3e1e31e8d6cdbfa3036cb183aa4a01
MD5 (openssh-3.2.2p1.tar.gz.sig) = be4f9ed8da1735efd770dc8fa2bb808a
Reportedly, the server hosting openssh, ftp.openbsd.org, was compromised recently. It has been reported that the intruder made modifications to the source code of openssh to include trojan horse code. Downloads of the openssh source code from ftp.openbsd.org between July 30, 2002 and July 31, 2002 likely contain the trojan code.
The trojan code appears to be included in the file, bf-test.c. Reports say that the trojan will run once upon compilation of openssh. The trojan process is named 'sh' or the compiling user's default shell. Once executed the trojan attempts to connect to 203.62.158.32 on port 6667. The trojan will then wait for one of three commands.
The following sites also have been reported to carry the trojaned version of openssh-3.4p1.tar.gz:
ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/
ftp://ftp.usa.openbsd.org/pub/OpenBSD/OpenSSH/
ftp://ftp1.se.openbsd.org/pub/OpenBSD/OpenSSH/
It is not known whether other sites are affected as well.
*** The OpenSSH team has released an advisory. Fixed versions of openssh are available for download since 1300 UTC August 1, 2002. The following MD5 checksum information was provided for fixed versions of openssh:
MD5 (openssh-3.4p1.tar.gz) = 459c1d0262e939d6432f193c7a4ba8a8
MD5 (openssh-3.4p1.tar.gz.sig) = d5a956263287e7fd261528bb1962f24c
MD5 (openssh-3.4.tgz) = 39659226ff5b0d16d0290b21f67c46f2
MD5 (openssh-3.2.2p1.tar.gz) = 9d3e1e31e8d6cdbfa3036cb183aa4a01
MD5 (openssh-3.2.2p1.tar.gz.sig) = be4f9ed8da1735efd770dc8fa2bb808a
Exploit / POC
OpenSSH Trojan Horse Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
OpenSSH Trojan Horse Vulnerability
Solution:
The vendor has fixed versions of openssh for download as of 1300 UTC August 1, 2002. They are available from the normal distribution channels and have the following MD5 checksums:
MD5 (openssh-3.4p1.tar.gz) = 459c1d0262e939d6432f193c7a4ba8a8
MD5 (openssh-3.4p1.tar.gz.sig) = d5a956263287e7fd261528bb1962f24c
MD5 (openssh-3.4.tgz) = 39659226ff5b0d16d0290b21f67c46f2
MD5 (openssh-3.2.2p1.tar.gz) = 9d3e1e31e8d6cdbfa3036cb183aa4a01
MD5 (openssh-3.2.2p1.tar.gz.sig) = be4f9ed8da1735efd770dc8fa2bb808a
Conectiva Linux has reported that openssh-3.4p1 is distributed as a security update. The distributed copy is the original one and is not affected by this trojan.
MandrakeSoft has verified that the openssh-3.4p1 sources used to build it's latest updates (MDKSA-2002:040-1) are not susceptible to this trojan.
IBM has stated that OpenSSH does not ship with AIX but is available via the Linux Affinity Toolkit. The version of OpenSSH included on the Toolkit CD is not vulnerable to this issue.
Solution:
The vendor has fixed versions of openssh for download as of 1300 UTC August 1, 2002. They are available from the normal distribution channels and have the following MD5 checksums:
MD5 (openssh-3.4p1.tar.gz) = 459c1d0262e939d6432f193c7a4ba8a8
MD5 (openssh-3.4p1.tar.gz.sig) = d5a956263287e7fd261528bb1962f24c
MD5 (openssh-3.4.tgz) = 39659226ff5b0d16d0290b21f67c46f2
MD5 (openssh-3.2.2p1.tar.gz) = 9d3e1e31e8d6cdbfa3036cb183aa4a01
MD5 (openssh-3.2.2p1.tar.gz.sig) = be4f9ed8da1735efd770dc8fa2bb808a
Conectiva Linux has reported that openssh-3.4p1 is distributed as a security update. The distributed copy is the original one and is not affected by this trojan.
MandrakeSoft has verified that the openssh-3.4p1 sources used to build it's latest updates (MDKSA-2002:040-1) are not susceptible to this trojan.
IBM has stated that OpenSSH does not ship with AIX but is available via the Linux Affinity Toolkit. The version of OpenSSH included on the Toolkit CD is not vulnerable to this issue.
References
OpenSSH Trojan Horse Vulnerability
References:
References: