LWN.net Logo

SSH plaintext recovery vulnerability

SSH plaintext recovery vulnerability

Posted Nov 21, 2008 23:32 UTC (Fri) by djm (subscriber, #11651)
In reply to: SSH plaintext recovery vulnerability by jbh
Parent article: SSH plaintext recovery vulnerability

Yes, the attack relies on the protocol's error behaviour to provide an "oracle" that verifies the guesses. However, this can't directly be used to recover keys - "just" plaintext that is sent over the SSH connection.


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds