Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE)

BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE)

From: Felipe Neuwald <felipe.neuwald_at_loreno.com.br>
Date: Mon, 12 Apr 2004 09:07:51 -0300

Hello Folks,

I tested only versions OpenSSH_3.5p1 (FreeBSD-STABLE), but it also work
on other versions, as published May 01, 2003.
Ok, let's talk about it. First, the /etc/ssh/sshd_config file:
<cut>
PermitRootLogin no
<cut>
As you can see above, is not allowed to root login on that system. Fine.
Now, trying login as root to the system, and type the wrong password:

felipe_at_worm felipe $ ssh -l root host
Password:
Password:
Password:
root_at_host's password:
Permission denied, please try again.
root_at_host's password:
Permission denied, please try again.
root_at_host's password:
Permission denied (publickey,password,keyboard-interactive).

And now, trying login as root to the system, but typing the correct
password:

felipe_at_worm felipe $ ssh -l root host
Password:
Connection to host closed by remote host.
Connection to host closed.

It's easy to make one little program to discover with bruteforce the
correct password of the root login. If the attacker have physical access
to the system, it's very easy own the system.
But... why still FreeBSD-STABLE are running this version of OpenSSH?

-- 
Felipe Neuwald
felipe.neuwald_at_loreno.com.br
+55 61 3038-5038
+55 61 9557-6870
------
Chave pública PGP / PGP public key:
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x8AE508F3

Received on Apr 12 2004
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]