Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
BugTraq
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
 
yet another OpenSSH timing leak? Oct 09 2006 10:33AM
Marco Ivaldi (raptor 0xdeadbeef info)
Hello Bugtraq,

Here we are again... During a recent penetration test i stumbled upon yet
another OpenSSH timing leak, leading to remote disclosure of valid
usernames. It's not as big as the one i found in the past (CVE-2003-0190),
but it can indeed be exploited over the Internet, nevertheless.

T...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus