Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
New SSH attack weakens passwords
Ann Harrison, SecurityFocus 2001-08-17

Researchers say the elapsed time between keystrokes can reveal much about your password.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
SSH Keystroke Timing Attack 2001-08-20
Chris Leonardos <cleonardos (at) triumph (dot) com [email concealed]>
My question is this: If the SSH Client caches the user keystrokes when accepting the password, and sends them only after the OK button is clicked, how can this attack be at all usefull?...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus