Exploitation of vulnerability in SSH1 CRC-32 compensation attack detector
Source: CERT.org
The CERT/CC has received multiple reports of systems being compromised via the CRC-32 compensation attack detector vulnerability described in VU#945216. We are also receiving reports of increased scanning activity for the SSH service (22/tcp).
This primarily applies to SSH Communications implementation of the SSH protocol. Systems using OpenSSH 2.3.0 or greater are not affected. Nonetheless, it contains information on how to reduce your susceptibility to SSH vulnerabilities in general.