Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
OpenSSH cutting edge
Federico Biancuzzi, 2005-12-19

Federico Biancuzzi interviews OpenSSH developer Damien Miller to discuss features included in the upcoming version 4.3, public key crypto protocols details, timing based attacks and anti-worm measures.

Comments Mode:
OpenSSH cutting edge 2005-12-21
Alex Blewitt (1 replies)
Re: OpenSSH cutting edge 2005-12-21
Kelly Martin
Editorial: alter use of HTML-comments 2005-12-21
Anonymous (1 replies)
OpenSSH cutting edge 2005-12-21
Anonymous (4 replies)
Re: OpenSSH cutting edge 2005-12-21
Anonymous (1 replies)
Re: Re: OpenSSH cutting edge 2005-12-22
Anonymous
Re: OpenSSH cutting edge 2005-12-21
Anonymous (1 replies)
Re: Re: OpenSSH cutting edge 2005-12-29
Anonymous
Re: OpenSSH cutting edge 2005-12-22
Anonymous (1 replies)
Re: Re: OpenSSH cutting edge 2005-12-29
Anonymous
Re: OpenSSH cutting edge 2005-12-22
Anonymous
TCP over TCP considered harmful 2005-12-22
Anonymous (3 replies)
Re: TCP over TCP considered harmful 2005-12-22
Anonymous (1 replies)
Re: Re: TCP over TCP considered harmful 2006-01-07
Anonymous
I'd doubt it, as I'd think TCP implementation being used is the one in the OS kernel, and I'm pretty sure there aren't any knobs you can switch on to get TCP to be unreliable and not to opmitimise it's behaviour for the available network capacity. Having those knobs would defeat the fundamental purposes of TCP. UDP is the appropriate protocol for applications to use if they don't want TCP's features.

The only option might be to implement "UDP" using TCP packets i.e. have SSH custom build packets that look like TCP, but not actually implement any of the TCP algorithms. The benefit would be that most firewalls probably don't watch TCP's algorithm's in action, and therefore would allow existing ssh permitting setups to work. There may be firewalls out there that do that TCP checking though, so the "UDP" in TCP technique may not be 100% guaranteed to work.



[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/375/32904#32904
Re: TCP over TCP considered harmful 2006-01-03
Baron von Leezard
Brute force attack 2005-12-22
Jules
OpenSSH cutting edge 2006-01-03
Anonymous (2 replies)
Re: OpenSSH cutting edge 2006-01-07
communIT
Re: OpenSSH cutting edge 2007-11-10
Anonymous
OpenSSH cutting edge 2006-01-24
Chris Kendon







 

Privacy Statement
Copyright 2007, SecurityFocus