http://www.linuxinsider.com/edpick/82991.html
I know a lot of users here are Linux gurus. Maybe this will be of interest.
Open SSH hacked, patch issued
- klikkyklik
- Location: America
- Main keyboard: Northgate Omni Key/102 w/Blue Alps
- Favorite switch: Blue Alps
- DT Pro Member: -
- Contact:
I saw that fix come through the Debian stable security repo recently. Yes, there was a problem and it's good that it's buttoned up, but if there is anyone that EVER uses an SSH client to connect to untrusted servers, I'd like to know why.
In other words, no biggy in the scope of things.
In other words, no biggy in the scope of things.
- scottc
- ☃
- Location: Remote locations in Europe
- Main keyboard: GH60-HASRO 62g Nixies, HHKB Pro1 HS, Novatouch
- Main mouse: Steelseries Rival 300
- Favorite switch: Nixdorf 'Soft Touch' MX Black
- DT Pro Member: -
Git ofen uses SSH as it's transport. An attacker would have to simply swap DNS records on a local router to point github.com to a malicious server and I bet many people would ignore the warning about the changed server signature.
- matt3o
- -[°_°]-
- Location: Italy
- Main keyboard: WhiteFox
- Main mouse: Anywhere MX
- Favorite switch: Anything, really
- DT Pro Member: 0030
- Contact:
my ssh client won't even log me in if the server signature changes...
- scottc
- ☃
- Location: Remote locations in Europe
- Main keyboard: GH60-HASRO 62g Nixies, HHKB Pro1 HS, Novatouch
- Main mouse: Steelseries Rival 300
- Favorite switch: Nixdorf 'Soft Touch' MX Black
- DT Pro Member: -
By default none log you in unless you've got StrictHostChecking no set, but in situations where DNS names are reused over and over (like tearing down and bringing up servers in AWS) you quickly run into situations where users might set that or ignore the warnings.
Plus, you never know when a legitimate friendly server has been compromised!
Plus, you never know when a legitimate friendly server has been compromised!
- webwit
- Wild Duck
- Location: The Netherlands
- Main keyboard: Model F62
- Favorite switch: IBM beam spring
- DT Pro Member: 0000
- Contact:
That would be like a burglar who is already in your house, trying to get your key of the front door.
- scottc
- ☃
- Location: Remote locations in Europe
- Main keyboard: GH60-HASRO 62g Nixies, HHKB Pro1 HS, Novatouch
- Main mouse: Steelseries Rival 300
- Favorite switch: Nixdorf 'Soft Touch' MX Black
- DT Pro Member: -
Or a key that opens every door on your employer's street if you've got automated systems and it's infeasible to have an individual key for each...