Skip to main content

Cute SSH Vulnerability

posted onOctober 23, 2001
by hitbsecnews

Here's another, somewhat fascinating reason to use your RSA keys with SSH: Berkeley researcher Dawn Xiaodong Song has figured out how to guess passwords typed into a shell over SSH by using statistical timing analysis. Here's an article about it. She's able to reduce brute force attacks on 7-8 character password by a factor of 50 with this approach. She points out some interesting tidbits about SSH that will help you out, but you'll have to read her paper to find them.

Source

Tags

Networking

You May Also Like

Recent News

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th

Friday, June 7th

Thursday, June 6th

Wednesday, June 5th