Re: On why debugging OpenSSH can be so hard
- From: "Vladimir Levijev" <vladimir.levijev@xxxxxxxxx>
- Date: Tue, 8 Jul 2008 10:24:59 +0300
2008/7/8, Ben Ford <ben@xxxxxxxxxxxxxx>:
No. He's saying that it leaks information that doesn't need to be leaked.
For comparison, long long ago, there used to be different error messages
when authentication failed. It would helpfully tell you that your password
was wrong, or that you'd supplied the wrong username. Great for debugging,
right? Well yeah ... and it was great for enumerating the users on the box,
making further attacks much simpler.
How about leaving what ssh server sends to the client as it is but
making it at least log in syslog that the key was not found?
VL
- References:
- Re: On why debugging OpenSSH can be so hard
- From: Tonnerre Lombard
- Re: On why debugging OpenSSH can be so hard
- From: Tonnerre Lombard
- Re: On why debugging OpenSSH can be so hard
- From: Tonnerre Lombard
- Re: On why debugging OpenSSH can be so hard
- From: Ben Ford
- Re: On why debugging OpenSSH can be so hard
- Prev by Date: Re: On why debugging OpenSSH can be so hard
- Next by Date: Re: SSH VPN trouble
- Previous by thread: Re: On why debugging OpenSSH can be so hard
- Next by thread: RE: On why debugging OpenSSH can be so hard
- Index(es):
Relevant Pages
|