6 ms·
PuTTY 0.66 fixes security vulnerability
- newman314 11y agoToo bad putty still doesn't support ed25519
- tetsefly 11y agoLooks like ed25519 was added in May 10th, 2015. [1] We claim version: SSH-2.0-PuTTY_Snapshot_2015_11_08.b003e5c Server version: SSH-2.0-OpenSSH_6.7p1 Debian-5 Using SSH protocol version 2 Doing ECDH key exchange with curve Curve25519 and hash SHA-256 Host key fingerprint is: ssh-ed25519 256 <fingerprint> Initialised ChaCha20 client->server encryption Initialised Poly1305 client->server MAC algorithm (in ETM mode) (required by cipher) Initialised ChaCha20 server->client encryption Initialised Poly1305 server->client MAC algorithm (in ETM mode) (required by cipher) I'm no expert, and this might not be what you are talking about, but to my untrained eye, it does? Now, to get back on topic, they believe that the attack would already need access to the server. "To exploit a vulnerability in the terminal emulator, an attacker must be able to insert a carefully crafted escape sequence into the terminal stream. For a PuTTY SSH session, this must be before encryption, so the attacker likely needs access to the server you're connecting to. For instance, an attacker on a multi-user machine that you connect to could trick you into running cat on a file they control containing a malicious escape sequence. (Unix write(1) is not a vector for this, if implemented correctly.)" [1] http://tartarus.org/~simon-git/gitweb/?p=putty-wishlist.git;a=blob;f=data/ed25519;h=d2d4b994da9245c2521eb25197d4a2632e2708b4;hb=740b9af900e7964fb56f79a08f257e5587c78fb0 http://tartarus.org/~simon-git/gitweb/?p=putty-wishlist.git;...
- MrRadar 11y agoEd25519 and ChaCha20-Poly1305 support are present in Git but not in any released version yet.
- zo1 11y agoLooks like there is an automatically-built set of binaries that run off the development branch. Have a look here: http://www.chiark.greenend.org.uk/~sgtatham/putty/download.html http://www.chiark.greenend.org.uk/~sgtatham/putty/download.h...
- sofaofthedamned 11y agoYou don't often see vulnerabilities in Putty, which considering the amount of corporate systems it's used with is quite amazing.
- hannob 11y agoIt may just mean nobody is looking at it.
- ipozgaj 11y agoI still don't understand why PuTTY got so popular (e.g. why not OpenSSH/Cygwin combo)
- AdmiralAsshat 11y agoI use PuTTY at my job because we do all of our development on a Linux server but have Windows laptops issued to us.
- el_duderino 11y agoShould check out XShell5. One of the best SSH clients I've used on Windows.
- ShakataGaNai 11y agoCygwin is a lot bigger and more time consuming to install. Putty is what? Half a meg and you're done? Much much much lower barrier to entry. There's also the issue that in a corporate environment, having a much smaller attack surface is greatly preferred. Trying to get something like Cygwin past the security dept in a BIG company - quite challenging.
- rincebrain 11y agoPuTTY is relatively portable, has just enough of a GUI to not require you use cmd.exe to run it, and is not GPL-ware. (To be clear, I have nothing against the GPL, but some corporate environments avoid it like the plague.)
- 11y ago
- fluffyllemon 11y ago> This bug was found with the help of American Fuzzy Lop
- frozenport 11y agoHow do you execute privileged code from this vulnerability (on the client?)? What is the worst case senario?
- consto 11y ago> To exploit a vulnerability in the terminal emulator, an attacker must be able to insert a carefully crafted escape sequence into the terminal stream. For a PuTTY SSH session, this must be before encryption, so the attacker likely needs access to the server you're connecting to. For instance, an attacker on a multi-user machine that you connect to could trick you into running cat on a file they control containing a malicious escape sequence. (Unix write(1) is not a vector for this, if implemented correctly.) From the sounds of it, an attacker needs to either compromise the machine you intend to ssh into, or mitm before you first ever connect. Once keys are cached you should easily notice if you've been mitmed.
- frozenport 11y agoYes, they need to compromise the server but they also need to compromise the client. With both compromised they will have the same execution privileges as the original Putty.exe, then they will need to ROPgadget? If they have both compromised by the heck do they need to use putty?
- Drdrdrq 11y agoNo, they must control the server, and with that they can compromise the client. Or at least this is how I understand it.
- nitrogen 11y agoAn attacker might just need to get something to show up into a log file that is then viewed using PuTTY. Always escape attacker-controlled data before logging or displaying it.
- 11y ago
- kilovoltaire 11y agodifficulty: fun: Just needs tuits, and not many of them. What does tuits mean?
- alblue 11y agoThere's a phrase "get a round tuit" which is a phonetical approxmaton of "get around to it". https://en.m.wiktionary.org/wiki/round_tuit https://en.m.wiktionary.org/wiki/round_tuit
- sjclemmy 11y agoyou just beat me tuit!
- McGlockenshire 11y agoI've also seen it used as a variation on "intuition."
- newsignup 11y agofuzzy lop seems to be quite handy since recently I saw a post here when they found 10s of bugs in ffmpeg.
- IshKebab 11y agoI think it was more like 1000...
- mlhamel 11y agoIs there anywhere sources of putty available?
- DanBC 11y agohttp://www.chiark.greenend.org.uk/~sgtatham/putty/download.html http://www.chiark.greenend.org.uk/~sgtatham/putty/download.h...
- UnoriginalGuy 11y agoI appreciate the hard work Simon Tatham continues to do on Putty. Has he said anything about the possibility of either signing the Putty executable or at least using HTTPS? Or is he waiting for Let's Encrypt to come on tap? He even references the threat on that page: "2015-05-19 Malware pretending to be PuTTY." Which would be a lot easier to detect if the software was signed.
- ehPReth 11y agoSee http://www.chiark.greenend.org.uk/~sgtatham/putty/keys.html http://www.chiark.greenend.org.uk/~sgtatham/putty/keys.html Also the.earth.li (PuTTY's download host) is available over HTTPS: https://the.earth.li/~sgtatham/putty/latest/x86/putty.exe https://the.earth.li/~sgtatham/putty/latest/x86/putty.exe But I do agree that HTTPS on both by default would be great
- UnoriginalGuy 11y agoThose keys aren't cross-signed (i.e. from a CA) and are delivered over HTTP. Totally and completely worthless. A bad guy could just replace them with their own keys (assuming anyone manually checked these to begin with) and I couldn't detect it.
- _wmd 11y agoYou don't appear to understand how the PGP web of trust works. The current release key is signed by the master key, which in turn has been signed by some keys which are indirectly cross-signed by a huge variety of developers many people are likely recognize. https://sks-keyservers.net/pks/lookup?op=vindex&search=putty%40projects.tartarus.org https://sks-keyservers.net/pks/lookup?op=vindex&search=putty... I guess it's true to say WOT is useless unless you participate in it, but at this stage, it is of comparable uselessness as the existing CA system.
- UnoriginalGuy 11y ago> You don't appear to understand how the PGP web of trust works. The current release key is signed by the master key, which in turn has been signed by some keys which are indirectly cross-signed by a huge variety of developers many people are likely recognize. Actually I do. It is just such a niche thing that for the few who will validate the key even fewer will check it on the P2P web of trust (and any person2person trust network is only as good as its members, so there is room for abuse there). Web of trust is a failed concept that the current CA structure destroyed. Worse still, some people will validate the key only, and if the executable validates they assume it must be by the author. That is a dangerous piece of misinformation that it gives a false sense of security, in particular against state actors. > I guess it's true to say WOT is useless unless you participate in it, but at this stage, it is of comparable uselessness as the existing CA system. When you download software on Windows, Mac, and Linux it will first automatically check if the code signing certificate's root CA is in the trusted store, then it will check that the root CA actually signed the client CA, and finally it will check the client CA for validity. It does all of this for you behind the scenes and in a split second, then at least on Windows & OS X it will display a huge warning if it fails (or fail to load the executable entirely by default). Essentially calling the current CA system "useless" is bizarre when it does all of this checking behind the scenes without any user intervention at all, and then warns the user when it fails. In particular when the web of trust is a convoluted mess of non-integrated software that less than 0.1% of users take advantage of, and even then need to manually remember to use and correctly interpret the result. The way Putty is signed is non-standard and insecure. Web of trust is a failed concept.
- mappu 11y agoMinTTY in Cygwin is based on the terminal emulation code from PuTTY, is it affected by the same CVE-2015-5309 ?
- voltagex_ 11y agoI'd also like to know this, but won't have time to check. There's also many many forks of PuTTY that'll need to be updated.
- MaulingMonkey 11y agoMy TtyRec player is PuTTY based <_<. Updates.
- fabulist 11y agodon't forget to restart, as well.
- Bud 11y agoYou know what I love about PuTTY? It's been around since the Clinton Administration (debuted in 1998), but it's still only at version 0.66. What will it take to get a version 1.0? Sentience?
- deleted 11y ago[deleted]
- vacri 11y agoMy favourite was the roguelike ADoM, which went up to 0.99, then alpha through gamma, then up to gamma 16, for a final version of 0.99gamma16 before tripping over to 1.0.