Re: OpenSSH & S/Key information leakage

From: Markus Friedl (markus@openbsd.org)
Date: 11/13/01


Date: Tue, 13 Nov 2001 13:00:04 +0100
From: Markus Friedl <markus@openbsd.org>
To: Joel Maslak <jmaslak@antelope.net>
Subject: Re: OpenSSH & S/Key information leakage
Message-ID: <20011113130004.A24212@faui02.informatik.uni-erlangen.de>

On Sun, Nov 11, 2001 at 06:29:38PM -0700, Joel Maslak wrote:
> There are some bad implementations of S/Key in client programs. OpenSSH
> (at least on OpenBSD 2.9) is one such bad implementation. OpenSSH only
> provides this challenge string if (1) the user exists and (2) the user is
> using one-time-passwords.

This depends very much on the version of the OpenSSH and the versions
of your skey library. OpenSSH switched away from creating fake skey
challenges, and now depends on the skey/otp/bsdauth/whatever-library to
created fake challenges. With BSD_AUTH it even depends on the
authentication algorithms available in the default class.

With a post-Nov 2000 OpenBSD, skeychallenge() creates fake challenges,
so OpenSSH does not need to care.



Relevant Pages

  • OpenSSH 3.6.1 released
    ... OpenSSH 3.6.1 has just been released. ... implementation and includes sftp client and server support. ... in a few other SSH v2 implementations and causes connections to ... new EnableSSHKeysign option is set in the global ssh_config ...
    (Bugtraq)
  • OpenSSH 3.6.1 released
    ... OpenSSH 3.6.1 has just been released. ... implementation and includes sftp client and server support. ... in a few other SSH v2 implementations and causes connections to ... new EnableSSHKeysign option is set in the global ssh_config ...
    (SSH)
  • Re: port
    ... > This is only true of some sftp implementations, such as OpenSSH. ... Thanks, Richard. ...
    (comp.security.ssh)
  • Re: TZ and HZ
    ... Roger Cornelius wrote: ... > It seems like this is more a problem of different implementations rather ... OpenSSH has all kinds of BROKEN_.... ... BROKEN usually means doesn't work like OpenBSD. ...
    (comp.unix.sco.misc)
  • Re: ssh 2 tunnel to named pipe not working - please help
    ... Protocol versions? ... Different implementations? ... suggests you were using OpenSSH and now are using ssh.com, ... Richard Silverman ...
    (comp.unix.admin)