L&LD
Part of the Furniture
SSH protects the world’s most sensitive networks. It just got a lot weaker
Novel Terrapin attack uses prefix truncation to downgrade the security of SSH channels.
checking to see where Dropbear lands here, as it was not immediately clear if it was affected or not...
Add "Strict KEX" support. This mitigates a SSH protocol flaw which lets
a MITM attacker silently remove packets immediately after the
first key exchange. At present the flaw does not seem to reduce Dropbear's
security (the only packet affected would be a server-sig-algs extension,
which is used for compatibility not security).
For Dropbear, chacha20-poly1305 is the only affected cipher.
Both sides of the connection must support Strict KEX for it to be used.
The protocol flaw is tracked as CVE-2023-48795, details
at https://terrapin-attack.com . Thanks to the researchers Fabian Bäumer,
Marcus Brinkmann, and Jörg Schwenk. Thanks to OpenSSH for specifying
strict KEX mode.
www.libssh.org
| Thread starter | Title | Forum | Replies | Date |
|---|---|---|---|---|
|
|
Rebooted laptop and saw a familiar yellow/black egg-timer after entering BIOS password (it's some kind of hack I don't know how is being installed). | General Network Security | 5 |
We use essential cookies to make this site work, and optional cookies to enhance your experience.