Re: ssh .vs. rsh

From: Atro Tossavainen (atossava_at_cc.helsinki.fi)
Date: 01/26/04

  • Next message: stalbertsoftball_at_shaw.ca: "VPN"
    To: secureshell@securityfocus.com
    Date: Mon, 26 Jan 2004 10:34:36 +0200 (EET)
    
    

    Robert,

    > If you're not worried about encrypting the X session then just turn off
    > the cypher or select none on your client. The login is still encrypted.

    You're mistaken. If you select the "none" cipher, nothing is encrypted.

    The "none" cipher might not be allowed on the client, or on the server,
    or on either. I am under the impression that it is disabled by default
    on OpenSSH, which is of course the sensible thing to do.

    -- 
    Atro Tossavainen (Mr.)               / The Institute of Biotechnology at
    Systems Analyst, Techno-Amish &     / the University of Helsinki, Finland,
    +358-9-19158939  UNIX Dinosaur     / employs me, but my opinions are my own.
    < URL : http : / / www . helsinki . fi / %7E atossava / > NO FILE ATTACHMENTS
    

  • Next message: stalbertsoftball_at_shaw.ca: "VPN"

    Relevant Pages

    • Re: SSL certificates and keys
      ... certificate is used if the clients do not support EC algorithms? ... if the server certificate contains a public key that the ... the client first announces what cipher suites it supports; ...
      (sci.crypt)
    • RE: verify HTTPS vulnerabilities
      ... the client is the one that tells the server first ... cipher suite combinations, which is what the Nessus script is probably doing ... The basic authentication thing also looks interesting. ...
      (Pen-Test)
    • Re: SSH vulnerability
      ... All I can see is that running sshd may not be too safe? ... very simple to recover the data. ... If you are in control of the client, you can specify the cipher. ...
      (alt.os.linux.suse)
    • RE: Penetration test of 1 IP address
      ... It does not look like the login screen found on the ... Penetration test of 1 IP address ... "I have been asked to perform a security audit of 1 IP address for client." ...
      (Pen-Test)
    • Re: Windows Login
      ... perfect...no public DNS servers used internally at all. ... We manage several hundred client networks. ... Windows XP desktops, Exchange 2003, WSUS deployments SQL, etc. ... CTRL-ALT-DEL, select Logoff, and RE-login, and they can login ...
      (microsoft.public.windows.server.setup)