Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Bugtraq: Re: BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE)

Re: BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE)

From: Damien Miller <djm_at_mindrot.org>
Date: Tue, 13 Apr 2004 21:41:39 +1000

BTW this is an old bug, that was discussed on bugtraq last year.

Felipe Neuwald wrote:
> Hello Folks,
>
> I tested only versions OpenSSH_3.5p1 (FreeBSD-STABLE), but it also work
> on other versions, as published May 01, 2003.

This bug existed in the PAM code of portable OpenSSH (not the OpenBSD
version), and was fixed before 3.7p1.

> It's easy to make one little program to discover with bruteforce the
> correct password of the root login. If the attacker have physical access
> to the system, it's very easy own the system.

You will likely be waiting a good while to guess any non-trivial
password.

This bug only exposes additional information when you find the
correct root password. You still have to search the entire keyspace with
no feedback to speed the search and you will have to reconnect every
three guesses.

Therefore, I don't agree that the impact of this old bug would make it
"very easy to own the system".

-d
Received on Apr 14 2004

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]