Posted Jul 7, 2009 18:30 UTC (Tue) by ncm (subscriber, #165)
Parent article: RUMOR: OpenSSH exploit
If I had discovered an exploit that only worked on new releases of OpenSSH, I might want to start such a rumor so my targets might make themselves vulnerable by installing such a release.
Posted Jul 7, 2009 18:32 UTC (Tue) by ESRI (guest, #52806)
[Link]
Alternately, if you discovered an exploit that worked only on an older version of OpenSSH, you might want to suggest what you just did so that we'd avoid installing a newer release and instead stick to the older, vulnerable version.
We're onto you!!
Works both ways
Posted Jul 7, 2009 20:50 UTC (Tue) by drfickle (guest, #1093)
[Link]
Inconceivable!
Works both ways
Posted Jul 8, 2009 7:34 UTC (Wed) by jengelh (subscriber, #33263)
[Link]
This is heavy. :-)
The question is ...
Posted Jul 8, 2009 21:39 UTC (Wed) by kmself (subscriber, #11565)
[Link]
... are you the kind of cracker who'd put the exploit in the version in
front of you, or the version in front of me?
Now ... where was I?
Works both ways
Posted Jul 8, 2009 1:05 UTC (Wed) by ncm (subscriber, #165)
[Link]