Rss Posts

Rss Comments



Bug Exposes OpenSSH Servers To Brute-Force Password Guessing Attacks

Jul 23

itwbennett writes: OpenSSH servers with keyboard-interactive authentication enabled, which is the default setting on many systems, including FreeBSD ones, can be tricked to allow many authentication retries over a single connection, according to a security researcher who uses the online alias Kingcope, who disclosed the issue on his blog last week. According to a discussion on Reddit, setting PasswordAuthentication to ‘no’ in the OpenSSH configuration and using public-key authentication does not prevent this attack, because keyboard-interactive authentication is a different subsystem that also relies on passwords.

Read more of this story at Slashdot.

View source

Comments are closed.