Re: Telnet Security Question for a Router.

From: Charley Hamilton (chamilto@uci.edu)
Date: 12/11/02

  • Next message: Sarbjit Singh Gill: "RE: NetScreen XP and NetMeeting"
    Date: Wed, 11 Dec 2002 13:27:55 -0800
    From: Charley Hamilton <chamilto@uci.edu>
    To: SECURITY-BASICS@securityfocus.com
    
    

    > The Network Services Group is adamant that neither SSH or
    > CISCO TACACS+ will work on a router to correct the security
    > issue.

    *blink blink*

    As a relative newbie/ignorant, I am distressed to hear that
    ssh doesn't "correct the security issues" with regard to
    clear-text username/password travel. Doesn't ssh send *all*
    traffic (from login to logoff inclusive) encrypted? Granted,
    no encryption is perfect, but take a large key and it'll take
    a while to decrypt, no? If you don't want to have passwords
    traveling at all, use keypairs with passphrases, with
    the keys stored on encrypted removable media. (That's my
    strategy for my ssh/sftp servers.)

    Is there something specific to routers that makes this solution
    inappropriate? Alternatively, is there some other problem with
    the routers that makes ssh and incomplete solution?

    Inquiring (newbie) minds want to know!

    Charley

    -- 
    Charles Hamilton, PhD EIT               Faculty Fellow
    Department of Civil and                 Phone: 949.824.3752
         Environmental Engineering           FAX:   949.824.2117
    University of California, Irvine        Email: chamilto@uci.edu
    


    Relevant Pages

    • Re: [Full-disclosure] Why Vulnerability Databases cant do everything
      ... best to relegate programming to a ... is a big difference between these two views of information security. ... but not nearly as important as designing secure systems. ... My favorite example to illustrate this point - ssh. ...
      (Bugtraq)
    • RE: Linux hacked
      ... Also, what exactly did the history file show, can you paste it into a mail ... > First let me say I'm a security novice. ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
      (Security-Basics)
    • Re: Secure Way of Remotely Viewing a Desktop...
      ... Remote Administrator (aka RAdmin) from Famatech. ... With respect to security, Famatech claims all data ... VNC tunneled through SSH ...
      (Security-Basics)
    • Questions on secure remote access to Fedora Core 2
      ... I am somewhat new to Internet security solutions in general and Linux ... I am setting up a server with Fedora Core 2 (there are specific reasons ... What is the most secure method I can use to give these individuals access ... under ssh. ...
      (comp.os.linux.security)
    • Re: Security basics
      ... I won't trust SSH alone. ... special iptables rules, and SELinux, to enhance the security of my ... I'd be interested to know what SElinux policy changes you've ... utility which sets up a client on the machine seeking the connection ...
      (Fedora)

    Loading