LINUX Unplugged

570: RegreSSHion Strikes


Listen Later

We dig into the RegreSSHion bug, debate it's real threat and explore clever tools to build a tasty fried onion around your system.

Sponsored By:

  • Core Contributor Membership: Take $1 a month of your membership for a lifetime!
  • Tailscale: Tailscale is a programmable networking software that is private and secure by default - get it free on up to 100 devices!
  • 1Password Extended Access Management: 1Password Extended Access Management is a device trust solution for companies with Okta, and they ensure that if a device isn't trusted and secure, it can't log into your cloud apps.
  • Support LINUX Unplugged

    Links:

    • đź’Ą Gets Sats Quick and Easy with Strike
    • đź“» LINUX Unplugged on Fountain.FM
    • Spokane Meetup - No-Li Brewhouse · JB Events on Gathio
    • Plasma/Krunner Docs — Brent's tip: 'https://search.nixos.org/options?query=\{@}' (the '\{@}' is the magic sauce)
    • autossh — Automatically restart SSH sessions and tunnels
    • autossh on GitHub
    • Spokane Meetup — No-Li Brewhouse, Sat, Jul 13, 2024, 4:00 PM
    • RegreSSHion — Remote Code Execution Vulnerability In OpenSSH Server
    • regreSSHion — Remote Unauthenticated Code Execution Vulnerability in OpenSSH server.
    • NixOS Security advisory: OpenSSH CVE-2024-6387 “regreSSHion” – update your servers ASAP
    • Nasty regreSSHion bug affects around 700K Linux systems
    • Qualys CVE-2024-6387 Write-up
    • Letmein: Authenticating port knocker - Written in Rust — Letmein is a simple port knocker with a simple and secure authentication mechanism. It can be used to harden against pre-authentication attacks on services like SSH, VPN, IMAP and many more.
    • fwknop: Single Packet Authorization > Port Knocking — fwknop stands for the "FireWall KNock OPerator", and implements an authorization scheme called Single Packet Authorization (SPA). This method of authorization is based around a default-drop packet filter
    • Membership Summer Discount — Take $1 a month of your membership for a lifetime!
    • Jeff links: How to run non-nix executables?
    • pick: stu — TUI (Terminal/Text UI) application for AWS S3
    ...more
    View all episodesView all episodes
    Download on the App Store

    LINUX UnpluggedBy Jupiter Broadcasting

    • 4.6
    • 4.6
    • 4.6
    • 4.6
    • 4.6

    4.6

    260 ratings


    More shows like LINUX Unplugged

    View all
    Security Now (Audio) by TWiT

    Security Now (Audio)

    1,970 Listeners

    The Changelog: Software Development, Open Source by Changelog Media

    The Changelog: Software Development, Open Source

    284 Listeners

    Coder Radio by The Mad Botter

    Coder Radio

    152 Listeners

    Late Night Linux by The Late Night Linux Family

    Late Night Linux

    154 Listeners

    Destination Linux by TuxDigital Network

    Destination Linux

    88 Listeners

    Home Assistant Podcast by HK Media

    Home Assistant Podcast

    65 Listeners

    The Linux Cast by The Linux Cast

    The Linux Cast

    35 Listeners

    This Week in Linux by TuxDigital Network

    This Week in Linux

    36 Listeners

    Linux Dev Time by The Late Night Linux Family

    Linux Dev Time

    21 Listeners

    Self-Hosted by Jupiter Broadcasting

    Self-Hosted

    135 Listeners

    Linux Out Loud by TuxDigital Network

    Linux Out Loud

    20 Listeners

    2.5 Admins by The Late Night Linux Family

    2.5 Admins

    92 Listeners

    Linux After Dark by The Late Night Linux Family

    Linux After Dark

    29 Listeners

    Linux & Open Source News by The Linux Experiment

    Linux & Open Source News

    21 Listeners

    Linux Matters by Linux Matters

    Linux Matters

    20 Listeners