<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6825&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / [SOLVED] Devuan bug #858 - just a heads-up]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6825</link>
		<description><![CDATA[The most recent posts in [SOLVED] Devuan bug #858 - just a heads-up.]]></description>
		<lastBuildDate>Thu, 05 Sep 2024 13:52:54 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52066#p52066</link>
			<description><![CDATA[<p>Good grief . . . that is some rabbit hole!</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Thu, 05 Sep 2024 13:52:54 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52066#p52066</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52063#p52063</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>ralph.ronnquist wrote:</cite><blockquote><div><p>... FUD whether you accept it or not.</p></div></blockquote></div><p>In my opinion, the concept of FUD is to a great extent and to say the least, subjective.<br />ie: without a proper evaluation of <em>intent</em>, <em>purpose</em> and <em>context</em> labelling something as FUD can be quite difficult if not risky.</p><p>To wit:<br />Alter Kim&#039;s post at the [devuan-dev] list was thoughtfully replied to by Mark Hindley (arguably Devuan&#039;s most prominent member) with a follow up by member tempforever with the addition of more information.</p><p>In both instances without <span class="bbu">any</span> mention of FUD spreading and such. ie: <em>intent</em>, <em>purpose</em> and <em>context</em> were evidently considered.</p><p>In a rather surprising follow up, <em>my</em> post here at Dev1 in which I cited the OPs post was met with a rather different demeanor, even after my posting a reply with an explanation of sorts.</p><p>@ralph.ronnquist<br />While I have the utmost respect for your knowledge and contrbution to the Dev1 project, I cannot but strongly disagree with your characterisation of my post as FUD.</p><p>So I&#039;ll leave this at that and (as far as I am concerned) agree to disagree, so to speak.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Thu, 05 Sep 2024 12:30:06 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52063#p52063</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52059#p52059</link>
			<description><![CDATA[<p>FUD at wikipedia:<br /><a href="https://en.wikipedia.org/wiki/Fear,_uncertainty,_and_doubt" rel="nofollow"> https://en.wikipedia.org/wiki/Fear,_uncertainty,_and_doubt</a></p><p>and a link from that wiki:<br /><a href="https://en.wikipedia.org/wiki/Eric_S._Raymond" rel="nofollow"> https://en.wikipedia.org/wiki/Eric_S._Raymond</a></p><p>which naturally reminded of:<br /><a href="https://dev1galaxy.org/viewtopic.php?id=2537" rel="nofollow"> https://dev1galaxy.org/viewtopic.php?id=2537</a></p><p>and a catchy tune(potential earworm?):<br /><a href="https://dev1galaxy.org/viewtopic.php?pid=14836#p14836" rel="nofollow"> https://dev1galaxy.org/viewtopic.php?pid=14836#p14836</a></p><p><a href="https://en.wikipedia.org/wiki/Earworm" rel="nofollow"> https://en.wikipedia.org/wiki/Earworm</a></p><p>enjoy</p>]]></description>
			<author><![CDATA[dummy@example.com (stargate-sg1-cheyenne-mtn)]]></author>
			<pubDate>Thu, 05 Sep 2024 06:34:24 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52059#p52059</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52055#p52055</link>
			<description><![CDATA[<p>Or putting it another way . . . there is no need to stir the pot if there is ultimately nothing there to stir.</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Thu, 05 Sep 2024 01:19:02 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52055#p52055</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52054#p52054</link>
			<description><![CDATA[<p>It was FUD whether you accept it or not. Sometimes a couple of thoughts before typing can do wonders.</p>]]></description>
			<author><![CDATA[dummy@example.com (ralph.ronnquist)]]></author>
			<pubDate>Thu, 05 Sep 2024 01:09:40 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52054#p52054</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52053#p52053</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>golinux wrote:</cite><blockquote><div><p>A &quot;bug report&quot; is not necessarily a &quot;bug&quot;.</p></div></blockquote></div><p>Indeed ...</p><p>I was citing a post at [devuan-dev] and thought it was something to be taken into account.<br />See: <a href="https://lists.dyne.org/lurker/message/20240904.094436.2e418da8.en.html" rel="nofollow">https://lists.dyne.org/lurker/message/2 … a8.en.html</a></p><p>But also <em>this</em>:</p><div class="quotebox"><cite>altoid wrote:</cite><blockquote><div><p>Like the subject reads, this is just a heads-up on my behalf.<br />I know zilch about all this ie: is it really a concern?<br />--- snip ---<br />Opinions/suggestions on how to proceed from those who understand this better are welcome.</p></div></blockquote></div><p>I think my post is a very (<span class="bbu">very</span>) long way from even the possibility of being characterised as the spreading of FUD.<br />Or <em>anything</em> of the sort.</p><p>Same for the OP at [devuan-dev] who clearly acted in good faith and did his research<br />I did not see his post characterised as FUD by anyone there.</p><p>Quite the contrary.</p><p>As for me, after over seven years and 1.527 posts at Dev1 ...<br />FUD?</p><p>Do lighten up. 8^P !!!</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Thu, 05 Sep 2024 01:02:40 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52053#p52053</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52050#p52050</link>
			<description><![CDATA[<p>@Altoid . . . A &quot;bug report&quot; is not necessarily a &quot;bug&quot;. In the future before posting about a &quot;bug&quot; it might be a good idea to wait until it has been verified by the Devuan devs that it actually IS a bug. No need to spread unnecessary FUD on this forum . . . <img src="https://dev1galaxy.org/img/smilies/wink.png" width="15" height="15" alt="wink" /></p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Wed, 04 Sep 2024 17:20:11 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52050#p52050</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52048#p52048</link>
			<description><![CDATA[<div class="codebox"><pre><code>$ ssh -G 2&gt;&amp;1 | grep -e illegal -e unknown &gt; /dev/null &amp;&amp; echo &quot;System clean&quot; || echo &quot;System infected&quot;</code></pre></div><p>A very convoluted bit of hand holding just to see if a command supports a &quot;-G&quot; option...&#160; the presence of a G option in no way conclusively proves malware is present...</p><p>FreeBSD (&quot;G&quot; clearly visible in the usage string) :</p><div class="codebox"><pre><code>% ssh -G
usage: ssh [-46AaCfGgKkMNnqsTtVvXxYy] [-B bind_interface] [-b bind_address]
           [-c cipher_spec] [-D [bind_address:]port] [-E log_file]
           [-e escape_char] [-F configfile] [-I pkcs11] [-i identity_file]
           [-J destination] [-L address] [-l login_name] [-m mac_spec]
           [-O ctl_cmd] [-o option] [-P tag] [-p port] [-R address]
           [-S ctl_path] [-W host:port] [-w local_tun[:remote_tun]]
           destination [command [argument ...]]
       ssh [-Q query_option]</code></pre></div><p>So this seems like it was a faulty test for malware, which should have instead focused on a check for a specific version.</p><div class="codebox"><pre><code>% ssh -V</code></pre></div>]]></description>
			<author><![CDATA[dummy@example.com (blackhole)]]></author>
			<pubDate>Wed, 04 Sep 2024 15:45:27 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52048#p52048</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52047#p52047</link>
			<description><![CDATA[<p>Resolved: <a href="https://lists.dyne.org/lurker/message/20240904.135001.ea767fe0.en.html" rel="nofollow">https://lists.dyne.org/lurker/message/2 … e0.en.html</a></p><div class="quotebox"><blockquote><div><p>I think you have missed the point that all current Devuan releases ship more<br />recent versions of OpenSSH than required by this test (6.7 or earlier):</p><p>openssh&#160; &#160; | 1:7.9p1-10+deb10u2 | oldoldstable&#160; &#160; &#160; &#160; &#160; &#160;| source<br />openssh&#160; &#160; | 1:7.9p1-10+deb10u2 | oldoldstable-debug&#160; &#160; &#160;| source<br />openssh&#160; &#160; | 1:8.4p1-2~bpo10+1&#160; | buster-backports&#160; &#160; &#160; &#160;| source<br />openssh&#160; &#160; | 1:8.4p1-2~bpo10+1&#160; | buster-backports-debug | source<br />openssh&#160; &#160; | 1:8.4p1-5+deb11u3&#160; | oldstable&#160; &#160; &#160; &#160; &#160; &#160; &#160; | source<br />openssh&#160; &#160; | 1:8.4p1-5+deb11u3&#160; | oldstable-debug&#160; &#160; &#160; &#160; | source<br />openssh&#160; &#160; | 1:9.2p1-2+deb12u3&#160; | stable&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;| source<br />openssh&#160; &#160; | 1:9.2p1-2+deb12u3&#160; | stable-debug&#160; &#160; &#160; &#160; &#160; &#160;| source<br />openssh&#160; &#160; | 1:9.8p1-8&#160; &#160; &#160; &#160; &#160; | testing&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160; | source<br />openssh&#160; &#160; | 1:9.8p1-8&#160; &#160; &#160; &#160; &#160; | unstable&#160; &#160; &#160; &#160; &#160; &#160; &#160; &#160;| source<br />openssh&#160; &#160; | 1:9.8p1-8&#160; &#160; &#160; &#160; &#160; | unstable-debug&#160; &#160; &#160; &#160; &#160;| source</p><p>-G is now a legitimate ssh option (see ssh(1)).</p><p>We have reviewed the article you provided and can find no evidence of compromise<br />of Devuan installations. It is also worth noting that all of Devuan&#039;s openssh<br />packages come directly from Debian, so it would likely be Debian that was<br />compromised.</p><p>I will close this report now, but if you feel we have misunderstood you or<br />missed something, please feel free to reopen.</p><p>Best wishes</p><p>Mark</p></div></blockquote></div><p>Tempest in a teapot . . .</p>]]></description>
			<author><![CDATA[dummy@example.com (golinux)]]></author>
			<pubDate>Wed, 04 Sep 2024 14:10:50 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52047#p52047</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52043#p52043</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>Delgado wrote:</cite><blockquote><div><p>Affected is version 6.7 or earlier ...</p></div></blockquote></div><p>The <a href="https://arstechnica.com/security/2024/05/ssh-backdoor-has-infected-400000-linux-servers-over-15-years-and-keeps-on-spreading/" rel="nofollow">article</a> at arstechnica makes reference to an issue from ~15 years ago, (apparently) still unpatched.</p><p>If so, yes.<br />If it is from as far back as 2019, it would affect Devuan from Jesse onwards.</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Wed, 04 Sep 2024 12:11:56 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52043#p52043</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52042#p52042</link>
			<description><![CDATA[<p>Hi,</p><p>I&#039;m confused about the ssh version. <a href="https://pkginfo.devuan.org/cgi-bin/policy-query.html?c=package&amp;q=openssh-server&amp;x=submit" rel="nofollow">https://pkginfo.devuan.org/cgi-bin/poli … r&amp;x=submit</a><br />Affected is version 6.7 or earlier, which would mean <strong>jessie</strong> (devuan 1 / debian 8) ?</p>]]></description>
			<author><![CDATA[dummy@example.com (delgado)]]></author>
			<pubDate>Wed, 04 Sep 2024 11:57:51 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52042#p52042</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52041#p52041</link>
			<description><![CDATA[<p>Hello:</p><div class="quotebox"><cite>sg1 wrote:</cite><blockquote><div><p>thanks ...<br />... we&#039;ll keep watching ...</p></div></blockquote></div><p>You&#039;re welcome.</p><p>Concurrently with the <a href="https://bugs.devuan.org/cgi/bugreport.cgi?bug=858" rel="nofollow">bug report</a> to Devuan, this was posted to the [devuan-dev] list.<br />So I expect that comments/clarifications will get posted <a href="https://lists.dyne.org/lurker/message/20240904.094436.2e418da8.en.html" rel="nofollow">there</a> first.</p><p>I wonder ...</p><p>Does this <span class="bbu">only</span> affect Devuan? Debian is not affected?</p><p>Best,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Wed, 04 Sep 2024 11:38:59 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52041#p52041</guid>
		</item>
		<item>
			<title><![CDATA[Re: [SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52039#p52039</link>
			<description><![CDATA[<p>thanks for posting this! we&#039;ll keep watching for thread updates!</p>]]></description>
			<author><![CDATA[dummy@example.com (stargate-sg1-cheyenne-mtn)]]></author>
			<pubDate>Wed, 04 Sep 2024 11:03:15 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52039#p52039</guid>
		</item>
		<item>
			<title><![CDATA[[SOLVED] Devuan bug #858 - just a heads-up]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=52035#p52035</link>
			<description><![CDATA[<p>Hello:</p><p>Just received <a href="https://lists.dyne.org/lurker/message/20240904.094436.2e418da8.en.html" rel="nofollow">this</a>.</p><p>My box runs on Devuan Daedalus, upgraded yesterday to <span class="bbc">6.1.106-3</span>:</p><div class="codebox"><pre><code>~$ uname -a
Linux devuan 6.1.0-25-amd64 #1 SMP PREEMPT_DYNAMIC Debian 6.1.106-3 (2024-08-26) x86_64 GNU/Linux
~$ </code></pre></div><p>I ran the test and it seems my system suffers from this bug*:<br />*?</p><div class="codebox"><pre><code>~$ ssh -G 2&gt;&amp;1 | grep -e illegal -e unknown &gt; /dev/null &amp;&amp; echo &quot;System clean&quot; || echo &quot;System infected&quot;
System infected
~$ uname -a</code></pre></div><p>Like the subject reads, this is <span class="bbu">just a heads-up</span> on my behalf.<br />I know zilch about all this ie: is it really a concern?<br />So I&#039;ll have to start reading up on it now, but not after I take my daily ration of espresso. 8^°</p><p>Opinions/suggestions on how to proceed from those who understand this better are welcome.<br />In any case, my workstation has no <span class="bbc">ssh</span> access (port 22 closed), only the headless VM running <span class="bbc">PiHole</span>+<span class="bbc">Unbound</span>.</p><p>Thanks in advance,</p><p>A.</p>]]></description>
			<author><![CDATA[dummy@example.com (Altoid)]]></author>
			<pubDate>Wed, 04 Sep 2024 10:36:57 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=52035#p52035</guid>
		</item>
	</channel>
</rss>
