Re: Apache Software Foundation Server compromised, resecured. (fwd)
From: Alex (alex@bsdfreak.org)
Date: 06/05/01
- Next message: Christopher Schulte: "Re: FreeBSD Security Advisory: FreeBSD-SA-01:40.fts"
- Previous message: Alex Holst: "Re: Apache Software Foundation Server compromised, resecured. (fwd)"
- In reply to: Alex Holst: "Re: Apache Software Foundation Server compromised, resecured. (fwd)"
- Next in thread: Borja Marcos: "Re: Apache Software Foundation Server compromised, resecured. (fwd)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Tue, 5 Jun 2001 13:49:58 -0400 (EDT) From: Alex <alex@bsdfreak.org> To: Alex Holst <a@area51.dk>
> Quoting Crist Clark (crist.clark@globalstar.com):
> > You cannot 'record passphrases.' RSA authentication uses public key
> > cryptography.
>
> Exactly. However, consider the three machines in the scenario below:
>
> workstation ---> compromised middle machine ---> server
>
> I have been thinking about the least risk approach. If the middle machine
> has ssh and sshd trojaned to various degrees, would one not benefit from
> using authentication forwarding rather than typing one's passphrase to the
> ssh client on the compromised machine?
This is a perfect scenario for the attack to perform a
man-in-the-middle attack, passive SSH analysis, or a brute force attempt
at the cryptographic integrity of the connection.
-Alex
>
> If one does lose his passphrase and the trojaned ssh captured the response
> it still wouldn't do an intruder much good, would it?
>
> --
> I prefer the dark of the night, after midnight and before four-thirty,
> when it's more bare, more hollow. http://a.area51.dk/
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message
- Next message: Christopher Schulte: "Re: FreeBSD Security Advisory: FreeBSD-SA-01:40.fts"
- Previous message: Alex Holst: "Re: Apache Software Foundation Server compromised, resecured. (fwd)"
- In reply to: Alex Holst: "Re: Apache Software Foundation Server compromised, resecured. (fwd)"
- Next in thread: Borja Marcos: "Re: Apache Software Foundation Server compromised, resecured. (fwd)"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|