pouring another cup of coffee and reading about openssh devs fixing problems for people trying to run the latest openssh portable release (10.2p1) on OSX 10.3 (Panther, circa 2003)
          
            October 17, 2025 at 12:20 PM
            
              
              Everybody can reply
            
          
        
          
          
          11 likes
          
        
        
      
    Catch up on the latest #Linux news: Ubuntu 25.10, Gnoppix KDE 25.10, GIMP 3.0.6, KDE Gear 25.08.2, OpenSSH 10.2, Python 3.14, ClamAV 1.5, Solus begins a new epoch, Meta unveils OpenZL, and more.
linuxiac.com/linuxiac-wee...
        
            linuxiac.com/linuxiac-wee...
Linuxiac Weekly Wrap-Up: Week 41 (Oct 6 – 12, 2025)
            Catch up on the latest Linux news: Ubuntu 25.10, Gnoppix KDE 25.10, GIMP 3.0.6, KDE Gear 25.08.2, OpenSSH 10.2, Python 3.14, ClamAV 1.5, Solus begins a new epoch, Meta unveils OpenZL, and more.
          
            
            linuxiac.com
          
        
          
            October 13, 2025 at 4:57 AM
            
              
              Everybody can reply
            
          
        
          
          
          1 likes
          
        
        
      
    Here's my latest experiment: a smolBSD microvm running an OpenSSH server with nitro github.com/NetBSDfr/smo...
          
            October 11, 2025 at 8:13 AM
            
              
              Everybody can reply
            
          
        
          3 reposts
          
          6 likes
          1 saves
        
        
      
    Faille sur OpenSSH, pas de panique, c'est dans le cas de l'utilisation de proxycommand (oui ça va faire chier pour les bastions)
cybersecuritynews.com/openssh-vuln...
        
            cybersecuritynews.com/openssh-vuln...
OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code - PoC Released
            A new command injection vulnerability in OpenSSH, tracked as CVE-2025-61984, has been disclosed, which could allow an attacker to achieve remote code execution on a victim's machine.
          
            
            cybersecuritynews.com
          
        
          
            October 7, 2025 at 4:05 PM
            
              
              Everybody can reply
            
          
        
          4 reposts
          
          19 likes
          3 saves
        
        
      
    OpenSSH 10.1 has just been released. This release includes several new features, a minor security fix and many other bugfixes.
Full release notes here: www.openssh.com/releasenotes...
        
          Full release notes here: www.openssh.com/releasenotes...
OpenSSH: Release Notes
            OpenSSH release notes
          
            
            www.openssh.com
          
        
          
            October 6, 2025 at 7:24 AM
            
              
              Everybody can reply
            
          
        
          4 reposts
          
          8 likes
          
        
        
      
    OpenSSH 10.1 is almost ready for release. Please help test - details at link below
marc.info?l=openssh-un...
        
          marc.info?l=openssh-un...
'Call for testing: OpenSSH 10.1p1' - MARC
            
          
            
            marc.info
          
        
          
            October 1, 2025 at 4:36 AM
            
              
              Everybody can reply
            
          
        
          2 reposts
          1 quotes
          8 likes
          
        
        
      
    various linux flavors are super fun in that sometimes things just fail silently or throw very unhelpful errors
personal favorite: are your packages broken? then apt in a bash shell will cheerfully go:
"openssh-server : Depends: openssh-client but it is not going to be installed"
          personal favorite: are your packages broken? then apt in a bash shell will cheerfully go:
"openssh-server : Depends: openssh-client but it is not going to be installed"
            September 16, 2025 at 2:13 PM
            
              
              Everybody can reply
            
          
        
          1 reposts
          
          28 likes
          1 saves
        
        
      
    Devcontainers are the reason why I use MS Visual Studio Code despite tracking and feature nudging. An alternative would be ZED, but it only supports remote editing via SSH.
It is possible to integrate SSH into a Docker container. In brief:
- Install openssh-server in the image
- Configuration […]
        
          It is possible to integrate SSH into a Docker container. In brief:
- Install openssh-server in the image
- Configuration […]
Original post on social.tchncs.de
            
          
            
            social.tchncs.de
          
        
          
            September 15, 2025 at 5:29 PM
            
              
              Everybody can reply
            
          
        
          
          
          2 likes
          
        
        
      
    #xz / liblzma have been compromised 🚨:
“OSS-Security – Backdoor In Upstream Xz/Liblzma Leading To SSH Server Compromise”, Andres Freund (www.openwall.com/lists/oss-se...).
On HN: news.ycombinator.com/item?id=3986...
On Lobsters: lobste.rs/s/uihyvs/bac...
#Security #OpenSSH #Compression
        
          “OSS-Security – Backdoor In Upstream Xz/Liblzma Leading To SSH Server Compromise”, Andres Freund (www.openwall.com/lists/oss-se...).
On HN: news.ycombinator.com/item?id=3986...
On Lobsters: lobste.rs/s/uihyvs/bac...
#Security #OpenSSH #Compression
oss-security - backdoor in upstream xz/liblzma leading to ssh server compromise
            
          
            
            www.openwall.com
          
        
          
            March 30, 2024 at 4:58 AM
            
              
              Everybody can reply
            
          
        
          
          
          1 likes
          
        
        
      
    New OpenSSH Flaw (CVE-2024-6409) Hits Red Hat Enterprise Linux 9
https://thecyberexpress.com/openssh-vulnerability/
##Infosec ##Security ##Cybersecurity ##CeptBiro ##OpenSSHFlaw ##RedHatEnterpriseLinux9
        
          https://thecyberexpress.com/openssh-vulnerability/
##Infosec ##Security ##Cybersecurity ##CeptBiro ##OpenSSHFlaw ##RedHatEnterpriseLinux9
New OpenSSH Flaw (CVE-2024-6409) Hits Red Hat Enterprise Linux 9
            A new security vulnerability has been discovered within select versions of the OpenSSH secure networking suite, potentially exposing systems to
          
            
            thecyberexpress.com
          
        
          
            July 10, 2024 at 2:40 PM
            
              
              Everybody can reply
            
          
        New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk
https://thehackernews.com/2024/07/new-openssh-vulnerability-discovered.html
##Infosec ##Security ##Cybersecurity ##CeptBiro ##OpenSSH ##Vulnerability ##RemoteCodeExecution ##Risk
        
          https://thehackernews.com/2024/07/new-openssh-vulnerability-discovered.html
##Infosec ##Security ##Cybersecurity ##CeptBiro ##OpenSSH ##Vulnerability ##RemoteCodeExecution ##Risk
New OpenSSH Vulnerability Discovered: Potential Remote Code Execution Risk
            OpenSSH vulnerability CVE-2024-6409 found in Red Hat Linux 9 may enable remote code execution. Discover more.
          
            
            thehackernews.com
          
        
          
            July 10, 2024 at 2:24 PM
            
              
              Everybody can reply
            
          
        Acceso remoto a un sistema Android que ejecuta Termux: ftp, ssh client, ssh agent, OpenSSH server, dropbear, sftp, mosh y rsync.
wiki.termux.com/wiki/Remote_...
        
          wiki.termux.com/wiki/Remote_...
Remote Access - Termux Wiki
            
          
            
            wiki.termux.com
          
        
          
            December 10, 2024 at 6:58 AM
            
              
              Everybody can reply
            
          
        Debian and Ubuntu release patch to fix OpenSSH vulnerabilities
        
            Debian and Ubuntu release patch to fix OpenSSH vulnerabilities
            Debian and Ubuntu have released updates for critical vulnerabilities in OpenSSH, including two high-severity flaws (CVE-2023-28531 and CVE-2023-51385) with a CVSS score of 9.8, and others (CVE-2021-41617, CVE-2023-48795, CVE-2023-51384) with varying severity, addressing issues ranging from command injection risks to unauthorized access and encryption protocol compromise.
          
            
            beyondmachines.net
          
        
          
            January 8, 2024 at 8:24 PM
            
              
              Everybody can reply
            
          
        
          1 reposts
          1 quotes
          1 likes
          
        
        
      
    #OpenSSH config recommendations in light of recent Snowden/NSA revelations
stribika.github.io/2015/01/04/sec…
        
          stribika.github.io/2015/01/04/sec…
Secure Secure Shell
            No ads, no tracking. Ever.<br/> <strong>blog.stribik.technology</strong> is completely static, without cookies or javascript.<br/> <strong>comments.stribik.technology</strong> uses javascript and local storage, it's loaded when you click
          
            
            stribika.github.io
          
        
          
            January 30, 2025 at 4:48 AM
            
              
              Everybody can reply
            
          
        Also note that as far as the attack is *currently* understood, Arch was not vulnerable to begin with as unlike Debian, Fedora etc. it does not link openssh to liblzma. However, better to be safe.
          
      Note: This is already fixed in Arch. Check that your xz package version is 5.6.1-2 with:
pacman -Q --info xz
xz --version will only display 5.6.1
lists.archlinux.org/archives/lis...
  pacman -Q --info xz
xz --version will only display 5.6.1
lists.archlinux.org/archives/lis...
            March 29, 2024 at 7:45 PM
            
              
              Everybody can reply
            
          
        ■Linuxクライアント/WindowsサーバでのOpenSSHを設定し直した🐻✨
5月に引っ越した際、ついでにメインPC(Windows)のメンテがてら工場出荷状態に戻した。
そのため、スマートスピーカ(Linux)からメインPCに、シャットダウンさせる(OpenSSHでしてシャットダウンコマンドを叩く)が、ここひと月ほどできない生活してた。
「わざわざ机まで行ってマウス操作してシャットダウンする」の、本当に不便だった……
これまで「Windows10」「11」「11(23H2)」で設定の仕方が微妙に違っていて(?)、毎回ちょっと手こずる///
          5月に引っ越した際、ついでにメインPC(Windows)のメンテがてら工場出荷状態に戻した。
そのため、スマートスピーカ(Linux)からメインPCに、シャットダウンさせる(OpenSSHでしてシャットダウンコマンドを叩く)が、ここひと月ほどできない生活してた。
「わざわざ机まで行ってマウス操作してシャットダウンする」の、本当に不便だった……
これまで「Windows10」「11」「11(23H2)」で設定の仕方が微妙に違っていて(?)、毎回ちょっと手こずる///
            June 9, 2024 at 3:16 PM
            
              
              Everybody can reply
            
          
        The badkeys.info project added the leaked and decrypted keys from the Fortinet breach: "Overall, there were around 100,000 private keys in PKCS format and 60,000 in OpenSSH format" blog.hboeck.de/archives/908...
        
          Private Keys in the Fortigate Leak  - Hanno's blog
            
          
            
            blog.hboeck.de
          
        
          
            January 17, 2025 at 5:55 PM
            
              
              Everybody can reply
            
          
        
          2 reposts
          
          5 likes
          
        
        
      
    SANS Stormcast Tuesday Feb 19th: ModelScan AI Model Security; OpenSSH Vuln; Juniper Patches; Dell BIOS Vulnerability
https://isc.sans.edu/podcastdetail/9330
          https://isc.sans.edu/podcastdetail/9330
            February 19, 2025 at 12:33 AM
            
              
              Everybody can reply
            
          
        
          1 reposts
          
          3 likes
          
        
        
      
    An unhinged experiment in rolling my own development tunnel solution, using nothing more than OpenSSH, Nginx, and a little bash.
0xda.de/blog/2024/04...
        
          0xda.de/blog/2024/04...
Can You Grok It
            My friend sent me a tunnel link where he had to manually set it up with socat and his nginx ingress controller in his k8s cluster. He made an offhand comment about needing a better way to setup tunnel...
          
            
            0xda.de
          
        
          
            April 14, 2024 at 3:27 AM
            
              
              Everybody can reply
            
          
        "“RegreSSHion” vulnerability in OpenSSH gives attackers root on Linux"
arstechnica.com?p=2035011
        
            arstechnica.com?p=2035011
“RegreSSHion” vulnerability in OpenSSH gives attackers root on Linux
            Full system compromise possible by peppering servers with thousands of connection requests.
          
            
            arstechnica.com
          
        
          
            July 3, 2024 at 6:26 AM
            
              
              Everybody can reply
            
          
        How to use Discord Reactive with 2-PC Setup: 
1. Install & Configure OpenSSH on both PCs.
          1. Install & Configure OpenSSH on both PCs.
            December 8, 2024 at 2:21 PM
            
              
              Everybody can reply
            
          
        
          1 reposts
          
          
          
        
        
      
    激ヤバ案件
> 複雑なプロセスを経て生成されたバックドアファイルを「OpenSSH」が読み込んでしまうと、認証をバイパスされてしまう可能性があるようだ。
しかも混入経過が凄すぎる…
forest.watch.impress.co.jp/docs/news/15...
        
            > 複雑なプロセスを経て生成されたバックドアファイルを「OpenSSH」が読み込んでしまうと、認証をバイパスされてしまう可能性があるようだ。
しかも混入経過が凄すぎる…
forest.watch.impress.co.jp/docs/news/15...
「XZ Utils」にバックドア、オープンソースエコシステム全体の信頼を揺るがす事態に/0.5秒の遅延からたまたま発覚、数年をかけた周到なやり口が明るみに
            Linux環境で広く利用されているツール「XZ Utils」に3月29日、バックドアが発見されたとのこと(CVE-2024-3094)。Red Hatが評価した「CVSS 3」のベーススコアは、「10.0」(Critical)。長い時間をかけてプロジェクトオーナーの信頼を勝ち取り、メンテナンスを任された開発者が意図的に混入させたという悪質性や、当該ツールが複数の主要なLinuxディストリビューショ...
          
            
            forest.watch.impress.co.jp
          
        
          
            April 1, 2024 at 1:58 AM
            
              
              Everybody can reply
            
          
        ICYMI: 📢 New in JProfiler 15: You can now use OpenSSH for remote profiling.
bsky.app/profile/ing...
        
            bsky.app/profile/ing...
Ingo Kegel (@ingokegel.bsky.social)
            1/ 📢 New in JProfiler 15:
 You can now use OpenSSH for remote profiling.
Connect to any machine using your local SSH setup — even through complex proxies or custom authentication methods.
          
            
            bsky.app
          
        
          
            May 14, 2025 at 1:04 PM
            
              
              Everybody can reply
            
          
         
        