¶þ½øÖÆÎļþÐ޸Ĺ¥»÷£¨³Ö¾Ã»¯£©ÏµÍ³ÉϳÖÐøÔËÐеÄÈí¼þ·þÎñÍùÍùÊǹ¥»÷Õß½øÐг־û¯¿ØÖƵÄ×îÓÐÀû¹¤¾ßÖ®Ò»¡£Èç¹û¿ÉÒÔÐÞ¸ÄϵͳÈí¼þ³ÌÐòµÄ¶þ½øÖÆÎļþʵÏÖ×Ô¶¨Ò幦ÄÜ£¬Í¬Ê±²»Ó°ÏìϵͳÈí¼þ·þÎñµÄÕý³£ÔËÐУ¬ÄÇô¾ÍÊÇÒ»¸ö·Ç³£ÍêÃÀµÄ³Ö¾Ã»¯¿ØÖÆ·½·¨¡£
´Ó¹¥»÷ÕߵĽǶÈÀ´·ÖÎö£¬ÔÚlinuxϵͳÖУ¬¹¥»÷Õß¿ÉÒÔͨ¹ýÐÞ¸Äopenssh²¿Êð°ü¶þ½øÖÆÎļþ£¬Ìí¼Ó¶ñÒâºóÃŲ¹¶¡£¬³Ö¾Ã»¯µØ»ñÈ¡sshµÇ¼Õ˺ÅÃÜÂ룬´ïµ½³Ö¾Ã»¯¿ØÖÆÊܺ¦Ö÷»úµÄÄ¿µÄ¡£
¸ù¾Ý¹¥»÷ÕßµÄÈëÇÖÁ÷³ÌºÍ²Ù×÷ÊֶΣ¬ÀûÓÃÐÞ¸ÄÈí¼þ¶þ½øÖÆÎļþ¹¥»÷ÔÚÈëÇÖ¹ý³ÌµÄÈëÇֳɹ¦Ö®ºó£¬¿ÉÒÔ°ïÖú¹¥»÷ÕßÔÚÈëÇֳɹ¦ºó³Ö¾Ã»¯µØ¿ØÖÆÊܺ¦Ö÷»ú£¬´ÓÈëÇÖÉúÃüÖÜÆÚ½Ç¶È·ÖÎö£¬ÐÞ¸ÄÈí¼þ¶þ½øÖÆÎļþ¹¥»÷¿É×÷ÓÃÓÚ¹¥»÷Õ߳־û¯½×¶Î¡£Ôڳ־û¯½×¶Î£¬¹¥»÷ÕßÀûÓÃÐÞ¸ÄÈí¼þ¶þ½øÖÆÎļþµÄÊֶλñÈ¡Ã÷ÎÄÆ¾Ö¤ÊµÏֳ־û¯¿ØÖÆ¡£
´Ó¹¥»÷ÐÐΪÁ´ÌõµÄÉÏÏÂÎÄÀ´¿´£¬Õë¶ÔÀûÓÃÐÞ¸ÄÈí¼þ¶þ½øÖÆÎļþ¹¥»÷µÄÐÐΪÁ´ÌõÊäÈëÊä³öÈçÏ£º
ÊäÈ룺openssh¶þ½øÖÆÎļþ¡¢opensshºóÃŲ¹¶¡Îļþ
Êä³ö£ºsshµÇ¼Ã÷ÎÄÕ˺ÅÃÜÂë
¸ù¾Ý²»Í¬¹¥»÷˼·£¬¹¥»÷ÕßÀûÓÃÐÞ¸ÄÈí¼þ¶þ½øÖÆÎļþµÄ¹¥»÷ÊÖ·¨Í¨³£ÓÐ1ÖÖ£º
1.ͨ¹ýÐÞ¸ÄopensshÔ´Âë´´½¨³Ö¾ÃºóÃŽٳÖÃ÷ÎÄÕ˺ÅÃÜÂë
Ê×ÏÈÏÂÔØopensshµÄÔ´Âë°ü
https://ftp.osuosl.org/pub/blfs/conglomeration/openssh/openssh-5.9p1.tar.gz

ÏÂÔØopensshºóÃÅÔ´Âë
http://core.ipsecs.com/rootkit/patch-to-hack/0x06-openssh-5.9p1.patch.tar.gz

ÕâÀï°²×°Ò»¸öcentos6.4µÄϵͳ½øÐвâÊÔ
https:
ʹÓÃssh -VÃüÁî²é¿´µ±Ç°openssh°æ±¾ÐÅÏ¢

yum°²×°ËùÐèÒÀÀµ°ü
yum -y install openssl openssl-devel pam-devel zlib zlib-devel

ÉÏ´«ÏÂÔØºÃµÄopensshÔ´Âë°üÒÔ¼°ºóÃÅÔ´ÂëÎļþµ½centosÖÐ

·Ö±ð½âѹѹËõ°üÎļþ
tar xf openssh-5.9p1.tar.gz
tar xf 0x06-openssh-5.9p1.patch.tar.gz

½«ºóÃÅÎļþ¼ÐÖеĺóÃŲ¹¶¡Îļþ¸´ÖƵ½opensshÎļþ¼ÐÖÐ
cp openssh-5.9p1.patch/sshbd5.9p1.diff openssh-5.9p1

ʹÓÃpatchÃüÁî´ò²¹¶¡
patch < sshbd5.9p1.diff

Ð޸ĺóÃÅÃÜÂë
vim includes.h

Ð޸İ汾ΪÔopensshÔö¼ÓÒþ±ÎÐÔ
vim version.h

°²×°gcc
yum install gcc

±àÒëÅäÖÃ
./configure --prefix=/usr --sysconfdir=/etc/ssh --with-pam --with-kerberos5

½øÐбàÒë
make && make install

±àÒëÍê³ÉºóÖØÆôssh£¬²é¿´µ±Ç°µÄopenssh°æ±¾ºÅÓëÔ°æ±¾ºÅÒ»ÖÂ
service sshd restart
ssh -V

ʹÓÃÕ˺ÅÃÜÂë½øÐÐsshÁ¬½Óºó£¬¼´¿ÉÔÚ/tmp/ilogÖп´µ½±£´æµÄÃ÷ÎÄÕ˺ÅÃÜÂë
cat /tmp/ilog
