3 ms·
Since this is a client side issue, can this be used to exploit those automated scanners who try to break into your SSH machine?
by sharjeel 11y ago
Since this is a client side issue, can this be used to exploit those automated scanners who try to break into your SSH machine?
- deleted 11y ago[deleted]
- dsr_ 11y agoNo. The scanners are looking for password-accessible accounts, not keyed accounts. The scanners won't have useful keys, nor listening ssh daemons.
- Stefan-H 11y agoAuthenticated scanners that use key auth like Qualys' security appliances could have private keys that are valid across the organization, and if using an affected client version, could leak this information to a malicious system on your network.