Netscreen ssh v.1 vulnerable??

From: Brian G. Kirsch (bkirsch@olosec.com)
Date: 05/24/02


From: "Brian G. Kirsch" <bkirsch@olosec.com>
To: <pen-test@securityfocus.com>
Date: Fri, 24 May 2002 12:12:49 -0700

In testing a Netscreen 5, I noticed that ssh v.1 compatibility is enabled
for remote management. The question is, is Netscreen vulnerable to the
various ssh v.1 vulnerabilities -- specifically the SSH1 CRC-32 compensation
attack detector vulnerability?

Thanks.

----------------------------------------------------------------------------
This list is provided by the SecurityFocus Security Intelligence Alert (SIA)
Service. For more information on SecurityFocus' SIA service which
automatically alerts you to the latest security vulnerabilities please see:
https://alerts.securityfocus.com/



Relevant Pages

  • SecurityFocus Microsoft Newsletter #196
    ... SecurityFocus ... MPlayer GUI File Name Buffer Overflow Vulnerability ... Relevant URL: http://www.securityfocus.com/bid/10612 ... Netegrity IdentityMinder is a tool designed for the Microsoft Windows platform to manage and maintain users and user accounts. ...
    (Focus-Microsoft)
  • Re: Medium Scale Scanning Best Practices
    ... network, ... > vulnerability rather than having to scan the entire network each time. ... > This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • SecurityFocus Microsoft Newsletter #191
    ... SecurityFocus ... MiniShare Server Remote Denial Of Service Vulnerability ... Relevant URL: http://www.securityfocus.com/bid/10409 ... Platforms: Windows 95/98, Windows NT ...
    (Focus-Microsoft)
  • RE: Scanners and unpublished vulnerabilities - Full Disclosure
    ... >> vulnerability. ... released with most of the other advisories. ... This list is provided by the SecurityFocus Security Intelligence Alert ... For more information on SecurityFocus' SIA service which ...
    (Pen-Test)
  • RE: Vulnebrability level definition
    ... > vulnerability to it will have maximum impact," even though ... >> This list is provided by the SecurityFocus Security ... >> Intelligence Alert Service. ... >> SecurityFocus' SIA service which automatically alerts you to ...
    (Pen-Test)