Any views expressed within media held on this service are those of the contributors, should not be taken as approved or endorsed by the University, and do not necessarily reflect the views of the University in respect of any particular issue.

Computing Systems

Computing Systems

Informatics Computing Staff jottings

SSH Service Compromise

In early October 2011 we discovered that the School of Informatics SSH service had been seriously compromised. Since that time our Computing Team has been working very hard to thoroughly investigate the circumstances of the event and provide a robust response.

As part of the response to this event we have written a detailled report. This covers the investigation and the initial
response. Furthermore, we have carried out a wide-ranging review of the design of our SSH service and made a number of proposals on how the security can be enhanced.

In the interests of helping other schools avoid experiencing the same problems we are making the report publically available. The report can be found on the DICE publications page.

It’s a fairly lengthy report, if you are not interested in the gory details of the investigation we recommend skipping to section 6 which is where the discussion and proposals section begins.

Leave a reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

css.php

Report this page

To report inappropriate content on this page, please use the form below. Upon receiving your report, we will be in touch as per the Take Down Policy of the service.

Please note that personal data collected through this form is used and stored for the purposes of processing this report and communication with you.

If you are unable to report a concern about content via this form please contact the Service Owner.

Please enter an email address you wish to be contacted on. Please describe the unacceptable content in sufficient detail to allow us to locate it, and why you consider it to be unacceptable.
By submitting this report, you accept that it is accurate and that fraudulent or nuisance complaints may result in action by the University.

  Cancel