4 ms·
While this question is aimed at SSH, be careful about a similar vector happening on more standard http username/email and password logins at any website. Most
by dotBen 10y ago
While this question is aimed at SSH, be careful about a similar vector happening on more standard http username/email and password logins at any website.
Most people use the same username or email address for all sites. It's pretty common to attempt to log in with the wrong password for that site, but one that is valid for other sites with the same credentials. While that password attempt shouldn't be logged, there's no guaranteeing it isn't - perhaps even via rouge admin and unbeknownst to the rest of the company.
The biggest threat here is email addresses as usernames, and attempting to login with the password that's actually used for the email account. Very easy to automate any incorrect (or correct) passwords against the original email account.
- nocman 10y ago"perhaps even via rouge admin" Those dang rouge admins (sorry, but I found that typo particularly amusing :-D). So, is a rouge admin embarrassed? Or is he just so terribly mad at the world that he has turned red?
- qwertyuiop924 10y agoAnd further more, are the rouge admins connected to the rouge angles of satin? Are these rouge admins satinic?