Re: Patching a SSH 'Weakness'

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Kevin Neff
Date: Friday, September 12, 2008 - 7:02 am

Thanks for all the comments.  I think we're all pretty much on the same
page.

First order of business is to look at how much of a weakness this may be.
Then, implement several potential solutions.  Finally, test to see if the
"fixes" improved the situation.

I like the idea of mainly patching the username and passwd transfer.  But
there may be some utility to having interactive sessions as bullet proof as
possible.

I will pitch the idea to my group.  If they agree to work on it, we will
have something by the end of the quarter (bar F).

--Kevin




On Fri, Sep 12, 2008 at 7:01 AM, Mike M <the.lists@mgm51.com> wrote:

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Patching a SSH 'Weakness', Kevin Neff, (Wed Sep 10, 12:58 pm)
Re: Patching a SSH 'Weakness', Damien Miller, (Wed Sep 10, 5:59 pm)
Re: Patching a SSH 'Weakness', Hari, (Wed Sep 10, 6:06 pm)
Re: Patching a SSH 'Weakness', Marco Peereboom, (Wed Sep 10, 6:50 pm)
Re: Patching a SSH 'Weakness', Darrin Chandler, (Wed Sep 10, 7:21 pm)
Re: Patching a SSH 'Weakness', STeve Andre', (Wed Sep 10, 7:56 pm)
Re: Patching a SSH 'Weakness', Aaron Glenn, (Wed Sep 10, 9:40 pm)
Re: Patching a SSH 'Weakness', Johan Beisser, (Wed Sep 10, 10:35 pm)
Re: Patching a SSH 'Weakness', Damien Miller, (Wed Sep 10, 11:28 pm)
Re: Patching a SSH 'Weakness', Paul de Weerd, (Thu Sep 11, 1:49 am)
Re: Patching a SSH 'Weakness', STeve Andre', (Thu Sep 11, 5:50 am)
Re: Patching a SSH 'Weakness', Giancarlo Razzolini, (Thu Sep 11, 8:06 am)
Re: Patching a SSH 'Weakness', Mike M, (Fri Sep 12, 5:01 am)
Re: Patching a SSH 'Weakness', Kevin Neff, (Fri Sep 12, 7:02 am)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 2:32 pm)