Subject: Re: OpenSSH Priv Sep and Remote Exploit?
To: None <sen_ml@eccosys.com>
From: Sean Davis <dive@endersgame.net>
List: tech-security
Date: 06/24/2002 19:22:27
Shouldn't we have 3.3 in basesrc/crypto/dist/ssh now? I know I saw commits
yesterday (or perhaps the day before) saying it was updated to 3.3, but
after a CVS update just now, I still get 3.2.1. I updated crypto/dist/ssh
and usr.bin/ssh, and see no differences. Am I doing something wrong?

Is anoncvs just updating slower than usual or something?

On Tue, Jun 25, 2002 at 08:17:38AM +0900, sen_ml@eccosys.com wrote:
> Answering my own question, I think (-;
> 
> From: sen_ml@eccosys.com
> Subject: OpenSSH Priv Sep and Remote Exploit?
> Date: Tue, 25 Jun 2002 07:48:18 +0900 (JST)
> 
> > As a side note, does anyone know how to check whether privilege
> > separation is enabled?
> 
> I presume checking whether there's a process that's running as the
> sshd user while in the process of establishing a connection is some
> evidence that privsep is working.

-- 
/~\ The ASCII                         Sean Davis
\ / Ribbon Campaign                    aka dive
 X  Against HTML
/ \ Email!                   http://endersgame.net/~dive/