Live data from Hacker News

OpenSSH: client bug CVE-2016-0777

undeadly.org

221–226 of 226 posts

Re: OpenSSH: client bug CVE-2016-0777

#221

My hardened ~/.ssh/config on OS X 10.11: Host * Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-256 KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256 HostKeyAlgorithms ssh-ed25519,ssh-rsa ChallengeResponseAuthentication no UseRoaming no If you only conne…

Funny story, I erroneously threw `UseRoaming no` on my server config and freaked the fuck out when I couldn't get into via SSH.

Six rescue sessions later, I figured out it shouldn't have been there ...

In the future, I'm definitely going to read documentation & test config files (sshd -t -f /path/to/sshd_config, in this case)

EDIT: Moral of the story, I am not a smart person sometimes.

Re: OpenSSH: client bug CVE-2016-0777

#222

Earlier quoted context omitted.

Pretty sure this is OpenSSH only. PuTTY and SecureCRT, at least, are reported not to be affected.

We use WinSCP also, a file copying utility; it would be useful to know whether that's affected if anybody has that info.

Last time I looked WinSCP used PuTTY components or a fork. Would appreciate additional verification of this, though.

Re: OpenSSH: client bug CVE-2016-0777

#223

Earlier quoted context omitted.

If an enemy takes control of just one of the hosts you ssh into, he will get your private key and can use it to ssh into any other box where you use RSAAuthentication.

I already added the mitigation, but I wondering if my servers can be patched on the weekend.

There is nothing to patch on the server side. You need to ensure the ssh client is updated on the machines you are sshing from.

Re: OpenSSH: client bug CVE-2016-0777

#224
This wasn't the only feature that was activated without much documentation. MaxSessions has a significant impact on any systems using 2FA (as the default allows bypassing it if you are phished).

Just like unrestricted sudo, people have because accustom to the bad default behavior of MaxSessions being 10 and allowing un-authenticated multiplexing. (meaning, you auth once, and my trojan can use your session without authentication)

Re: OpenSSH: client bug CVE-2016-0777

#225

Earlier quoted context omitted.

I already added the mitigation, but I wondering if my servers can be patched on the weekend.

There is nothing to patch on the server side. You need to ensure the ssh client is updated on the machines you are sshing from.

ok thanks, that's what I figured, but it I was getting a bit worried that I was missing something.

Re: OpenSSH: client bug CVE-2016-0777

#226
Having been through some difficult times when i had been let down by everyone around me, i came across Brandon Reid who is a hacker its actually impossible to put in words how much of a Genius he is and also cant stop thanking him for helping me through my divorce, and also my Nephews grades. He is a Blackhat hacker and very capable of almost and everything, he is actually one of the best out there and also shows you proof before charging you, in my own case the money wasnt the problem and i can gladly say every money spent was so worth it. I have reffered a number of people who will prefer not to be named to Brandon and all have been immensly satisfied with the Top Notch hacking service Brandon offers.To whoever who is lucky enough to read this its a new year and i am only doing this for those genuine people out there who would want the services of a hacker please as i said before be careful how you speak to him his a BigFish. He can be contacted on his services email Brandonreid001@gmail.com or text +1 813 379 2141 . Do mention the name Jade
Post reply on HN