From owner-freebsd-security Fri Nov 26 12:45:40 1999 Delivered-To: freebsd-security@freebsd.org Received: from anarcat.dyndns.org (phobos.IRO.UMontreal.CA [132.204.20.20]) by hub.freebsd.org (Postfix) with ESMTP id 40CA615E21 for ; Fri, 26 Nov 1999 12:45:25 -0800 (PST) (envelope-from spidey@anarcat.dyndns.org) Received: by anarcat.dyndns.org (Postfix, from userid 1000) id 6DCA41B33; Thu, 25 Nov 1999 22:44:40 -0500 (EST) From: Spidey MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Message-ID: <14398.543.747440.547183@anarcat.dyndns.org> Date: Thu, 25 Nov 1999 22:44:31 -0500 (EST) To: relapz Cc: freebsd-security@FreeBSD.ORG Subject: Re: Fwd: ssh-1.2.27 remote buffer overflow - exploitable (VD#7) References: <199911160357.UAA01885@harmony.village.org> X-Mailer: VM 6.72 under 21.1 "20 Minutes to Nikko" XEmacs Lucid (patch 2) Reply-To: Spidey Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --- Big Brother told relapz to write, at 11:27 of November 16: > seeing as we are on the OpenSSH/ssh front, i've decided to ditch ssh in > favour of OpenSSH. > > However, I seem to be getting some odd errors when someone connects to the > new OpenSSH server daemon: > > Nov 16 11:18:35 <4.4> frosty sshd[1146]: set class 'default' resource > limit datasize: Operation not permitted > Nov 16 11:18:35 <4.4> frosty sshd[1146]: set class 'default' resource > limit stacksize: Operation not permitted > Nov 16 11:18:35 <4.4> frosty sshd[1146]: set class 'default' resource > limit maxproc: Operation not permitted > Nov 16 11:18:35 <4.4> frosty sshd[1146]: set class 'default' resource > limit openfiles: Operation not permitted > > Can someone shed some light on what exactly causes these? Should i be > worried about a misconfig or is this normal. thanx, I found out that putting 'UseLogin yes' in the config file solved the problem. Does anybody knows the implications of using that options? Thanks the AnarCat -- Si l'image donne l'illusion de savoir C'est que l'adage pretend que pour croire, L'important ne serait que de voir Lofofora To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message