Your HostICan Community  


Go Back   Your HostICan Community > HostICan Web Hosting > Virtual Private Servers (VPS)

Virtual Private Servers (VPS) Need help with your VPS plan on HostICan? Please feel free to ask and we'll give you the answers!

Reply
 
Thread Tools Search this Thread Display Modes
  #1  
Old 05-25-2009, 05:19 PM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Question Security issues

  1. How can we update openssh? The command
    Code:
    yum update openssh
    does not update past version 3.9. As the servers are using an old version, there are exploits and connectivity issues with some applications. To fix the connectivity issues, the version needs to be past 4.x.
  2. Also, there is a bug (that's what Hostican told me) that is preventing cpHulk and the firewall to run on my VPS servers. This has been an issue for a couple months at least, and there have been security issues as a result of this. When will this be fixed?
  3. Finally, what is the timetable to update the servers. One of the guys here told me that CentOS 4.x is no longer actively supported with security fixes, updates, etc. (I don't know if that's true, as I've not checked the CentOS site to see yet). He suggested I ask when servers will be updated to CentOS 5.x as it is a stable release.
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy
Reply With Quote
  #2  
Old 05-27-2009, 10:26 AM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Default Re: Security issues

***Bump***
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy
Reply With Quote
  #3  
Old 05-27-2009, 12:26 PM
DOCENTA's Avatar
DOCENTA DOCENTA is offline
Moderator
 
Join Date: Sep 2007
Posts: 96
Default Re: Security issues

Hello,
Just use:

# yum update


and all will be updated to the latest versions available.
__________________
Thanks,

HostICan Rocket Scientist

HostICan Answers | HostICan Newsletter | HostICan Blog | Become a HostICan Affiliate | Create a Support Ticket.
Reply With Quote
  #4  
Old 05-27-2009, 02:31 PM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Default Re: Security issues

Quote:
Originally Posted by DOCENTA View Post
Hello,
Just use:

# yum update


and all will be updated to the latest versions available.
No that is NOT true. As mentioned in the post, yum will not take openssh past version 3.9 (which is very old).

Can Hostican please answer the three questions - THANKS!
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy

Last edited by roger; 05-27-2009 at 02:34 PM.
Reply With Quote
  #5  
Old 05-28-2009, 10:08 AM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Default Re: Security issues

***Bump***
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy
Reply With Quote
  #6  
Old 05-29-2009, 12:29 PM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Default Re: Security issues

***Bump***
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy
Reply With Quote
  #7  
Old 05-29-2009, 12:48 PM
DOCENTA's Avatar
DOCENTA DOCENTA is offline
Moderator
 
Join Date: Sep 2007
Posts: 96
Default Re: Security issues

OS default OpenSSH is good you do not need to mess with it.
__________________
Thanks,

HostICan Rocket Scientist

HostICan Answers | HostICan Newsletter | HostICan Blog | Become a HostICan Affiliate | Create a Support Ticket.
Reply With Quote
  #8  
Old 05-29-2009, 01:13 PM
KODY's Avatar
KODY KODY is offline
Junior Member
 
Join Date: Jan 2009
Posts: 25
Default Re: Security issues

Hello mister, from where you know that OpenSSH_3.9 in CeontOS is vulnerable? Are you sure that this applies specifically to OpenSSH, perhaps you mean OpenSSL? About the exploit, there is last know exploit:
Code:
2008-07-17 Debian (maybe other derivates |KUDUBUTUNTU|) OpenSSH Remote -=Authenticated=- SELinux Privilege Elevation
Lets see. HostICan use CenotOS, not Debian. And second, which is also important, SELinux support is DISABLED. Please, have trust fully of updates which are provided by the repository of CentoOS. I think the guys from CentoOS are not rookies people and would not allow any bugs to crash impeccable reputation of the best secured Linux
Reply With Quote
  #9  
Old 05-30-2009, 08:18 AM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Default Re: Security issues

Everyone is missing other issues mentioned. Version 4/5 are now standard. Most apps dont work with less than version 3 (SSH).

Also, there are 3 questions.

Does Hostican not support this forum? I was told to put some questions here, but then they don't get answered properly.

@KODY - This is not a CentOS vs some other OS issue, I use both CentOS and Debian based with no problems. Sites on this server have been going up and down regularly. I've been concerned and asked someone to look at it. The first thing they said was that much of the files were old and outdated. It's not about one expolit in the version of SSH, rather about several issues, that cooperatively allow security breaches.

@Hostican - A short while back, I did notice a performance improvement in the servers (I have 4 of them), but now perfomance is not good. Please can you answer the above. Also, there is a ticket from about April that has still to be resolved - You told me you would make sure the issue is fixed, but it is not.
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy

Last edited by roger; 05-30-2009 at 08:18 AM. Reason: spelling
Reply With Quote
  #10  
Old 06-01-2009, 01:20 PM
roger's Avatar
roger roger is offline
Senior Member
 
Join Date: Sep 2007
Posts: 286
Default Re: Security issues

***Bump***
__________________
I'm about finding and using the best tools; and advice to obtain the best exposure for your online presence - BloggerSavvy. Don't forget to follow me on twitter: @BloggerSavvy
Reply With Quote
Reply

Tags
centos, cphulk, firewall, issues, openssh, security, update

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT -4. The time now is 03:48 PM.


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.

Copyright © 2003 - 2008 HostICan. All Rights Reserved.