4 msgapt-get upgrade rückgängig machen
1 msgRe: [SECURITY] [DSA 1050-1] New ClamAV packages...
2 msgAW: [SECURITY] [DSA 1048-1] New Asterisk packag...
1 msgIntelligent Investor Report
1 msgRE: RuAmerica Job
4 msgRe: [SECURITY] [DSA 1041-1] New abc2ps packages...

UsePAM in /etc/ssh/sshd_config and timing attacks
\ Alexandros Papadopoulos (24 Apr 2006)

9 msgLogauswertung
1 msg[Fwd: [Pkg-dia-team] Bug#364293: dia-common_0.9...
7 msgSecurity status of mozilla-* packages
2 msgRe: Re: postfix in qmail out proftpd in pureftpd
10 msgDebian Kernel security status?
4 msgPam module for hylafax
1 msgRE: [SECURITY] [DSA 1033-1] New horde3 packages...
5 msgPHP4 vulnerabilities
1 msgdebsums online database
3 msgIDS for a non-well-known protocol?
1 msgRe: [SECURITY] [DSA 1018-2] New Linux kernel 2....
1 msgRe: [SECURITY] [DSA 1027-1] New mailman package...
4 msgRe: [SECURITY] [DSA 1024-1] New clamav packages...
Subject:UsePAM in /etc/ssh/sshd_config and timing attacks
Group:Debian-security
From:Alexandros Papadopoulos
Date:24 Apr 2006


 
Dear all

People have been complaining for too long that timings attacks are
possible because of the way OpenSSH responds to keyboard-interactive
authentication.

With the variance in the delay of response, it makes it obvious whether
the username it tries to authenticate indeed exists on the remote
machine or not.

A few days ago De Raadt sent an email to BUQTRAQ blaming this
information leakage to PAM.

So, one would expect that the directive UsePAM in the sshd configuration
file would help one get around this issue.

But although I have "UsePam no", I still see the same behavior (variance
in response time).

Can this be resolved somehow?

Cheers

-A


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com