5 ms·
Yes, it appears to be a timing attack where invalid users are denied more quickly than valid users. https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh
by jdwithit 10y ago
Yes, it appears to be a timing attack where invalid users are denied more quickly than valid users.
https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_enumusers https://www.rapid7.com/db/modules/auxiliary/scanner/ssh/ssh_...
- jeffmcjunkin 10y agoAnd to be clear, this is an issue that resurfaced in August or so of 2016, and is patched in supported OpenSSH daemons[0][1]. [0] https://access.redhat.com/security/cve/cve-2016-6210 https://access.redhat.com/security/cve/cve-2016-6210 [1] https://www.ubuntu.com/usn/usn-3061-1/ https://www.ubuntu.com/usn/usn-3061-1/