Re: virtual terminal dump

From: Hal Flynn (flynn@securityfocus.com)
Date: 10/24/01


Date: Wed, 24 Oct 2001 13:01:57 -0600 (MDT)
From: Hal Flynn <flynn@securityfocus.com>
To: <focus-linux@securityfocus.com>
Subject: Re: virtual terminal dump
Message-ID: <Pine.GSO.4.30.0110241251480.3320-100000@mail>


> Basically, you want to snoop upon the SSH session. There is something you
> have to understand. SSH means Secure Shell. It's built for security. The
> whole point of using SSH rather than regular telnet is to have a SECURE,
> ENCRYPTED connection so that no one can snoop upon it.

This is a misnomer. Secure Shell implies that the connection between
endpoints is secure, or cryptographically "secured." However, the data
still has to traverse multiple insecure layers, ala shell, kernel, etc.

This is one reason replacing the ssh and sshd programs with trojaned
versions is so popular. Doing so allows one to intercept traffic prior to
it being encrypted.

Hal Flynn
UNIX Focus Area Manager
SecurityFocus

"Semper Fidelis"



Relevant Pages

  • Re: telnet replacement - not ssh?
    ... they could set up a secure box that you can log ... Then ssh from that box to your systems. ... > usually keep the main session unencrypted so your snoops can snoop. ... They're obviously not security people if they want logs of what ...
    (comp.security.misc)
  • Re: telnet replacement - not ssh?
    ... they could set up a secure box that you can log ... Then ssh from that box to your systems. ... > usually keep the main session unencrypted so your snoops can snoop. ... They're obviously not security people if they want logs of what ...
    (comp.security.ssh)
  • Re: telnet replacement - not ssh?
    ... they could set up a secure box that you can log ... Then ssh from that box to your systems. ... > usually keep the main session unencrypted so your snoops can snoop. ... They're obviously not security people if they want logs of what ...
    (comp.security.unix)
  • Re: [Full-disclosure] Why Vulnerability Databases cant do everything
    ... best to relegate programming to a ... is a big difference between these two views of information security. ... but not nearly as important as designing secure systems. ... My favorite example to illustrate this point - ssh. ...
    (Bugtraq)
  • Questions on secure remote access to Fedora Core 2
    ... I am somewhat new to Internet security solutions in general and Linux ... I am setting up a server with Fedora Core 2 (there are specific reasons ... What is the most secure method I can use to give these individuals access ... under ssh. ...
    (comp.os.linux.security)