Re: in.telnetd vulnerability??
From: Ryan Russell (ryan@securityfocus.com)Date: 08/03/01
- Previous message: Darren Moffat: "IPsec vs SSH (Was Re: in.telnetd vulnerability??)"
- In reply to: Stephen J Fralich: "Re: in.telnetd vulnerability??"
- Next in thread: adam morley: "Re: in.telnetd vulnerability??"
- Next in thread: adam morley: "Re: in.telnetd vulnerability??"
- Reply: adam morley: "Re: in.telnetd vulnerability??"
- Reply: Brian Hatch: "Re: in.telnetd vulnerability??"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Fri, 3 Aug 2001 15:50:44 -0600 (MDT) From: Ryan Russell <ryan@securityfocus.com> To: Stephen J Fralich <sjfralic@ecs.syr.edu> Subject: Re: in.telnetd vulnerability?? Message-ID: <Pine.GSO.4.30.0108031544460.1584-100000@mail>
On Thu, 2 Aug 2001, Stephen J Fralich wrote:
> ssh is used for any administrative work, but I'll let you come tell my
> users they have to run a different program or *gasp* install a new program
> on their own machines if they want to use the systems...heresy!! Well,
> until the system get's compromised...then it would be why wasn't the
> system more secure?
I wonder how hard it would be to write a version of the SSH client named
telnet that would try port 22 before failing to port 23, and do plain
telnet when used on other ports (telnet mail.example.com 110). Claim it
is the new telnet client patch. It would allow for some cleartext
downgrade attacks, but that would at least require active monitoring and
spoofing. If it were called by the name "ssh", very soft links, it would
behave normally.
Hmm... maybe I need to go work on a patch.
Ryan
- Previous message: Darren Moffat: "IPsec vs SSH (Was Re: in.telnetd vulnerability??)"
- In reply to: Stephen J Fralich: "Re: in.telnetd vulnerability??"
- Next in thread: adam morley: "Re: in.telnetd vulnerability??"
- Next in thread: adam morley: "Re: in.telnetd vulnerability??"
- Reply: adam morley: "Re: in.telnetd vulnerability??"
- Reply: Brian Hatch: "Re: in.telnetd vulnerability??"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|