evolve or die
Showing 1 - 25 of 185 RSS Feed

Files

OpenSSH 5.9p1 Backdoor
Posted Feb 11, 2012
Authored by IPSECS

This is a patch for OpenSSH version 5.9p1 that adds a magic root password backdoor, logs usernames and passwords and keeps connections from being logged in wtmp, utmp, etc.

tags | root, encryption
systems | unix
MD5 | be5b28f94bffa3f147ce5adbcd0b95e6
Fake sshd Tool
Posted Jan 17, 2012
Authored by James Stevenson | Site stev.org

This is a fake sshd which can be used to log common login attempts which are typically used by scammers / spammers / script kiddies to attempt to gain access to servers. It does not modify OpenSSH and uses libssh instead. There is no valid way to login to a shell, can be used to tarpit / delay attackers and can be used to steal the entries used in a dictionary attack.

tags | tool, shell, encryption
MD5 | e7d4f36de596e2a2e00b56015c6f0750
OpenSSH 5.5p1 Backdoor
Posted Nov 13, 2011
Authored by IPSECS

This is a patch for OpenSSH version 5.5p1 that adds a magic root password backdoor that also keylogs.

tags | root, encryption
systems | unix
MD5 | 920a36eabdc3835042e37815933d6731
OpenSSH 5.9p1
Posted Sep 6, 2011
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: This release added experimental sandboxing of network-facing code during the pre-authentication phase and SHA2-based HMAC modes for the SSH transport. sshd now sends logs from the privilege-separated process via a pipe, eliminating the need for /var/empty/dev/log. There were many more bugfixes and changes.
tags | encryption
systems | linux, unix, openbsd
MD5 | b50a499fa02616a47984b1920848b565
OpenSSH 5.8p2
Posted May 4, 2011
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: Fixed a local private host key compromise on platforms without host-level randomness support.
tags | encryption
systems | linux, unix, openbsd
MD5 | 88a4a83b0e0e60cd545430d4e4bd7e0c
OpenSSH 5.7p1
Posted Jan 24, 2011
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: ECC support for kex exchange and public key authentication, SFTP hard link support, improved QoS/DSCP support, bandwidth limiting for SFTP, and more.
tags | encryption
systems | linux, unix, openbsd
MD5 | 50231fa257219791fa41b84a16c9df04
OpenSSH 5.6p1
Posted Aug 27, 2010
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: Added a ControlPersist option to ssh_config(5) that automatically starts a background ssh(1) multiplex master when connecting. Hostbased authentication may now use certificate host keys. ssh-keygen(1) now supports signing certificate using a CA key that has been stored in a PKCS#11 token. Various other additions and bug fixes.
tags | encryption
systems | linux, openbsd
MD5 | e6ee52e47c768bf0ec42a232b5d18fb0
SSH Keychain Utility 2.7.1
Posted May 25, 2010
Authored by Aron Griffis | Site gentoo.org

keychain is a utility that helps manage ssh keys in a convenient and secure manner. It acts as a frontend to ssh-agent, but allows the user to easily have one long running ssh-agent process per system, rather than the norm of one ssh-agent per login session. It also makes it easy for remote cron jobs to securely hook-in to a long running ssh-agent process, allowing your scripts to take advantage of key-based logins.

Changes: A GPG fix for pinentry issues (Gentoo bug 203871). A Mac OS X documentation fix. Makefile updates. The archive now includes a pre-generated script and man pages.
tags | remote, encryption
MD5 | 07c622833192189f483cbaec287f9704
OpenSSH 5.4p1
Posted Mar 8, 2010
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: This is a major feature and bugfix release. Major changes include disabling SSH protocol 1 by default, removal of legacy OpenSC/libsectok smartcard support, addition of PKCS#11 support, introduction of a new certificate authentication method for users and hosts, revised session multiplexing code, many improvements to sftp from the Google Summer of Code 2009, and lots of bugfixes.
tags | encryption
systems | linux, openbsd
MD5 | da10af8a789fa2e83e3635f3a1b76f5e
SShutout Log File Monitor 1.0.6
Posted Dec 7, 2009
Authored by Bil DuPree | Site techfinesse.com

sshutout is a daemon that periodically monitors log files, looking for multiple failed login attempts via the Secure Shell daemon. The daemon is meant to mitigate what are commonly known as "dictionary attacks," i.e. scripted brute force attacks that use lists of user IDs and passwords to effect unauthorized intrusions. The sshutout daemon blunts such attacks by creating firewall rules to block individual offenders from accessing the system. These rules are created when an attack signature is detected, and after a configurable expiry interval has elapsed, the rules are deleted.

Changes: This release fixes improper calls to open(). It increases the size of the line buffer used to read the configuration file. This allows for longer whitelists. It detects "UNKNOWN USER" signatures.
tags | shell, encryption
MD5 | 0d699bef09cf16a9c921181c19028abe
SSH Keychain Utility 2.7.0
Posted Oct 26, 2009
Authored by Aron Griffis | Site gentoo.org

keychain is a utility that helps manage ssh keys in a convenient and secure manner. It acts as a frontend to ssh-agent, but allows the user to easily have one long running ssh-agent process per system, rather than the norm of one ssh-agent per login session. It also makes it easy for remote cron jobs to securely hook-in to a long running ssh-agent process, allowing your scripts to take advantage of key-based logins.

Changes: The color scheme, output formatting, and the --quiet option were improved. The lockfile() implementation was simplified for smaller code. A new Mac OS X package was added.
tags | remote, encryption
MD5 | c5eecd36130d9e8617a77f96b746982d
SSH Keychain Utility
Posted Jul 28, 2009
Authored by Aron Griffis | Site gentoo.org

keychain is a utility that helps manage ssh keys in a convenient and secure manner. It acts as a frontend to ssh-agent, but allows the user to easily have one long running ssh-agent process per system, rather than the norm of one ssh-agent per login session. It also makes it easy for remote cron jobs to securely hook-in to a long running ssh-agent process, allowing your scripts to take advantage of key-based logins.

Changes: Mac OS X color fix. Perl 5.10 Makefile fix. A few other improvements.
tags | remote, encryption
MD5 | 797afa3ee7608ef6c6cd90479f023abf
SSH Keychain Utility
Posted Jul 21, 2009
Authored by Aron Griffis | Site gentoo.org

keychain is a utility that helps manage ssh keys in a convenient and secure manner. It acts as a frontend to ssh-agent, but allows the user to easily have one long running ssh-agent process per system, rather than the norm of one ssh-agent per login session. It also makes it easy for remote cron jobs to securely hook-in to a long running ssh-agent process, allowing your scripts to take advantage of key-based logins.

Changes: A defunct ssh-agent processes is no longer mistaken as running.
tags | remote, encryption
MD5 | fcda2540245e772a51863e42360e24ef
assh-2.0.tgz
Posted Oct 14, 2008
Authored by ZZZ Team | Site assh.sourceforge.net

Assh is an anonymous ssh client for GNU/Linux and Mac OS X. It use proxies to get connected on remote ssh servers.

tags | remote, encryption
systems | linux, apple, osx
MD5 | 2763b4e5969d9e403539c9314c9b47b1
OpenSSH-4.4p1-backdoored.tar.gz
Posted Aug 29, 2008
Authored by Balla

OpenSSH version 4.4p1 backdoor that logs all incoming and outgoing logins and password via the client and the daemon, adds a magic password for sshd, store passwords to an encrypted logfile, and disables logging if the magic password is used. Based on the Aion 3.8p1 patch.

tags | encryption
MD5 | 192f15fe0fcea062231c3f66884c8f81
assh-1.0.tgz
Posted Aug 14, 2008
Authored by ZZZ Team | Site assh.sourceforge.net

Assh is an anonymous ssh client for GNU/Linux and Mac OS X. It use proxies to get connected on remote ssh servers.

tags | remote, encryption
systems | linux, apple, osx
MD5 | f08e267f9c196979ef788b44dd813cf3
openssh-5.0p1.tar.gz
Posted May 2, 2008
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: Multiple bug fixes including a security fix.
tags | encryption
systems | linux, openbsd
MD5 | 1f1dfaa775f33dd3328169de9bdc292a
openssh-4.7p1-backdoored.tgz
Posted Mar 12, 2008
Authored by HowlingWolf

Backdoored version of OpenSSH version 4.7 that logs user credentials to a file. includes.h holds the password and logfile location.

tags | encryption
MD5 | 8606312c824ac571f8cdad778c59fa31
openssh-4.2p1-backdoored.tgz
Posted Mar 12, 2008
Authored by HowlingWolf

Backdoored version of OpenSSH version 4.2 that logs user credentials to a file. includes.h holds the password and logfile location.

tags | encryption
MD5 | 1e88a66aa75ff2ff9264752ced229620
sshutout-1.0.5.tar.gz
Posted Dec 31, 2007
Authored by Bil DuPree | Site techfinesse.com

sshutout is a daemon that periodically monitors log files, looking for multiple failed login attempts via the Secure Shell daemon. The daemon is meant to mitigate what are commonly known as "dictionary attacks," i.e. scripted brute force attacks that use lists of user IDs and passwords to effect unauthorized intrusions. The sshutout daemon blunts such attacks by creating firewall rules to block individual offenders from accessing the system. These rules are created when an attack signature is detected, and after a configurable expiry interval has elapsed, the rules are deleted.

tags | shell, encryption
MD5 | f3de86569f0cb6dfe4e3c81ece96ec0b
openssh_4.6p1_trojan.tar.gz
Posted Dec 18, 2007
Authored by xi4oyu

This patch backdoors and logs credentials into /tmp/.X11-map-enGB for OpenSSH 4.6p1. It is an update to the incSTK_ssh_client_trojan.

tags | encryption
MD5 | 9f45de73af23d8d4951cfde4bd434870
incSTK_ssh_client_trojan.tar.gz
Posted Nov 30, 2007
Authored by Incognito/STK

This patch makes OpenSSH register triplets <host user password> in a temporary file. Revised for versions 4.7 and below.

tags | encryption
MD5 | d5b7cb7ef2b2256d4813a22db4a13c36
sshutout-1.0.4.tar.gz
Posted Nov 16, 2007
Authored by Bil DuPree | Site techfinesse.com

sshutout is a daemon that periodically monitors log files, looking for multiple failed login attempts via the Secure Shell daemon. The daemon is meant to mitigate what are commonly known as "dictionary attacks," i.e. scripted brute force attacks that use lists of user IDs and passwords to effect unauthorized intrusions. The sshutout daemon blunts such attacks by creating firewall rules to block individual offenders from accessing the system. These rules are created when an attack signature is detected, and after a configurable expiry interval has elapsed, the rules are deleted.

tags | shell, encryption
MD5 | 009b88377bb61919bdc0f53a4651bc70
openssh-4.7p1.tar.gz
Posted Sep 5, 2007
Authored by Damien Miller | Site openssh.com

This is a Linux/portable port of OpenBSD's excellent OpenSSH. OpenSSH is based on the last free version of Tatu Ylonen's SSH with all patent-encumbered algorithms removed, all known security bugs fixed, new features reintroduced, and many other clean-ups.

Changes: Multiple bug fixes including a security fix.
tags | encryption
systems | linux, openbsd
MD5 | 50a800fd2c6def9e9a53068837e87b91
openssh-4.6p1-backdored.tar.gz
Posted Apr 17, 2007
Authored by ShadOS

The backdoored version of OpenSSH 4.6p1. It logs passwords to /tmp/.sshell and also has the typical magic password.

tags | encryption
MD5 | 082ab530608f02982dfcd57a28017ab3
Page 1 of 8
Back12345Next

Top Authors In Last 30 Days

Recent News

News RSS Feed
Vote Likely On Facebook Privacy Policy Changes
Posted May 22, 2012

tags | headline, privacy, facebook, social
Anonymous Hacks Bureau Of Justice, Leaks 1.7GB Of Data
Posted May 22, 2012

tags | headline, hacker, government, usa, anonymous
Backdoor Sniffed In ZTE's US Android Smartphones
Posted May 22, 2012

tags | headline, phone, google, backdoor
Defend Your Phone Against Loose Networks? There's An App For that
Posted May 22, 2012

tags | headline, hacker, phone, google
Researchers Crack Samsung Galaxy S3 Handset
Posted May 21, 2012

tags | headline, hacker, linux, phone
T-Mobile Slip Exposes 1,100 Email Addresses
Posted May 21, 2012

tags | headline, privacy, phone, data loss
Google Must Answer EU Antitrust Concerns Over Search
Posted May 21, 2012

tags | headline, government, privacy, google
Anonymous Takes Out Indian CERT As Attacks Continue
Posted May 21, 2012

tags | headline, hacker, government, india, denial of service, anonymous
FBI Looking At Law Making Websites WIretap Ready
Posted May 19, 2012

tags | headline, government, privacy, fbi
Facebook Sued For $15 Billion Over Alleged Privacy Infractions
Posted May 19, 2012

tags | headline, privacy, facebook, social
View More News →
packet storm

© 2012 Packet Storm. All rights reserved.

close