16 ms·
Targeted MitM attacks using information leakage in SSH clients [pdf]
- based2 6y agohttps://www.chiark.greenend.org.uk/~sgtatham/putty/ https://www.chiark.greenend.org.uk/~sgtatham/putty/ 2020-06-27 PuTTY 0.74 released
- noble_pleb 6y agoAn alternative to putty on windows is to get the entire Git SCM package[1]. You get not just git, ssh and sftp but many other useful command line tools too. [1]: https://git-scm.com/ https://git-scm.com/
- AnssiH 6y agoNote also that ssh and scp (from OpenSSH) are included in Windows by default since 2018.
- cpach 6y agoWSL is, IMHO, another good option.
- doublerabbit 6y agoAnother alt is Cygwin https://cygwin.com/ https://cygwin.com/
- kbuck 6y agoWindows 10 comes with OpenSSH installed by default now -- start up PowerShell and run `ssh`. Includes all the trimmings, even a `ssh-agent`. Of course, if you don't like the rendering/look/customization of the default PowerShell window, you can also grab Windows Terminal: https://www.microsoft.com/en-us/p/windows-terminal/9n0dx20hk701 https://www.microsoft.com/en-us/p/windows-terminal/9n0dx20hk...
- ziml77 6y agoI use msys2 directly instead. https://www.msys2.org/ https://www.msys2.org/
- Kenji 6y agoThe article is so low on details. I wish there was a more in-depth explanation. Isn't the first connection (with unknown host key) always a target for MitM attacks and thus insecure, unless you preload the host key?
- Xylakant 6y agoThe leak allows an attacker to distinguish first connections that are made without a cached host key, allowing them to target those connections only and reduce their risk of detection. OpenSSH seems affected, too, but have decided to not fix this. As far as I understand the paper, any fix may have undesirable side effects. The linked paper here https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/ https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2... goes into detail. The PDF is in English, despite the German URL.
- Randor 6y agoYes, That is exactly the reported issue here. PuTTY 0.68 through 0.73 allows the remote attacker to accurately determine whether or not the client has cached the host key. It looks like this works because PuTTY sends a different algorithm list depending on whether or not the key has been cached. If the MiTM attacker sees the 'default algorithm list' it can be assumed that this is the first connection attempt and the attacker can substitute the server key with a compromised key.
- 8organicbits 6y agoAh, that's cool. I pushed AWS to give better ways of getting the host key for new EC2 instances a few years back. The whole start an EC2 instance, SSH in and blinkly trust the host key on first use thing seemed terrible! EC2 docs now include that detail, although its labeled as optional. https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connection-prereqs.html#connection-prereqs-fingerprint https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/connecti...
- DangerousPie 6y agoI'm surprised people are still using PuTTY this much. It used to be one of the first programs I'd install on any new Windows machine and has served me well for many years. But since I started using WSL I haven't needed it once.
- bluedino 6y agoIs the terminal emulation fixed? Every time I tried to use WSL, some kind of glitch shows up when I am SSH’d into a server.
- demosito666 6y agoIt's not. Default wsl terminal is pretty much unusable if you need anything more complex than entering commands (read vim and tmux). You can install MinTTY terminal for wsl, but it's much more hassle then just download putty.
- m0xte 6y agoYeah it’s awful. Window terminal default key bindings buggers up touch as well. I have moved to macOS since wsl2 came out.
- nvr219 6y agoI use it only when I need to connect via serial
- vbezhenar 6y agoI'm using PuTTY because I prefer native software. That said, it seems that Microsoft started shipping its own build of OpenSSH with Windows 10, so probably that's not needed anymore.
- cafard 6y agoThe terminal emulation in Windows 10 isn't great. Mostly I use PuTTY instead.
- zokier 6y agoAccording to the report, this also applies to OpenSSH client
- dang 6y agoYes. The versions are OpenSSH 5.7 - 8.3, PuTTY 0.68 - 0.73. We've changed the URL from https://nvd.nist.gov/vuln/detail/CVE-2020-14002 https://nvd.nist.gov/vuln/detail/CVE-2020-14002 to what seems to be the original source, via https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/ https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2..., which the former article links to. The comments in this thread are all about PuTTY, which no doubt is because that's all the other article mentioned.
- badrabbit 6y agoThe EU has a $90k bounty for bugs in putty,did anyone collect on this?
- tinus_hn 6y agoIf you don’t know the host key you are always vulnerable to a man in the middle attack. Is this really a vulnerability in Putty or a design weakness in SSH?
- gruez 6y agoIt's an intentional design decision. Unlike https, ssh doesn't typically use x509 certificates for authentication, so there's no real way to know whether you're MITM if you're making a connection for the first time.
- RL_Quine 6y agoSSH supports things like pinning the key in a DNSSEC response.
- tptacek 6y agoModern SSH of course does support certificates --- SSH certificates aren't X.509 --- which solve this problem, the key management problem, and the long-term SSH key hazmat problem. Probably, SSH certificates are what we should have been using all along.
- nickysielicki 6y agoThere's a lot said about the benefits of competing implementations: browsers, web frameworks, what-have-you. There are certain categories of security-critical software where I feel like it's only increasing surface area for bugs. The idea that PuTTY has bugs that aren't originating from the openssh project is really bothersome to me. All that work to reimplement, for what?
- Wowfunhappy 6y agoOn the other hand, this bug only affects PuTTY users instead of all openssh users, which means it’s that much less of an appealing target for Hackers.
- Xylakant 6y agoThis bug actually affects OpenSSH, too. See https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients/ https://www.fzi.de/en/news/news/detail-en/artikel/fsa-2020-2...
- asveikau 6y agoVery surprised to see a bug get patched in putty but says OpenSSH won't fix. Anyone reading this with the kind of background who can comment on that?
- Xylakant 6y agoIf I read the report correctly, this is a protocol level issue. The report lists a potential client side fix, but it’s not without problems and includes the following sentence regarding openssh: “ The developers of OpenSSH are not planning to change the behavior of OpenSSH regarding this issue, because of the aforementioned drawbacks. ”
- james412 6y agoPuTTY was written back in a time when SSH was proprietary software. It predates the first release of OpenSSH, which I believe was BSD-only at the time, by almost a year. That aside, the official SSH implementation has never been any princess either. The PuTTY implementation is superior in many ways, not least in terms of modularity, although evidently just as prone to security problems as OpenSSH. I'm all for new alternative implementations of important pieces of our stack, but please God no more security-critical C.
- maxheadrum 6y agoDoes anyone else get sketched out about downloading putty from the official URL? I know its been around for awhile, but still seems like a suspect URL for such a popular program.
- notRobot 6y agoNah, it's normal to have URLs like that for software, especially for power user or administration or developer utilities.
- gnu8 6y agoEveryone recognizes that URL. It would be more suspect to download PuTTY from anywhere else.
- maxheadrum 6y agoI recognize the general pattern of the URL but if you changed a character here or there I wouldn't notice it.
- pmoriarty 6y agoAs an infrequent user of PuTTY, I don't recognize that URL. So I guess I'm not part of the "everyone" you're talking about. On the other hand, I think it's absolutely ridiculous to base one's security around URL recognition, considering all the possible attacks against domain names and URLs. Cryptographic signatures in a web of trust would be a big step forward here, but unfortunately relatively few people participate.
- gruez 6y ago> Everyone recognizes that URL. It would be more suspect to download PuTTY from anywhere else. that that to everyone who downloaded from putty.org
- dehrmann 6y agoThe lack of any style on the page tells you it's legit.
- jlgaddis 6y agoIt's a good idea to explicitly set the "Ciphers", "HostKeyAlgorithms", "KexAlgorithms", and "MACs" options to your preferred values (in your ssh_config and sshd_config files) anyways... but, as a bonus, the issue doesn't affect you if you have (according to the document).
- elric 6y agoMozilla has a pretty good guide for those config options: https://infosec.mozilla.org/guidelines/openssh.html https://infosec.mozilla.org/guidelines/openssh.html
- floatingatoll 6y agoIf you set these options yourself rather than depending on your upstream distro defaults, be prepared to experience surprising and unexpected incompatibilities with SSH; by making your own choices, you are accepting additional responsibilities for debugging compatibility issues that will arise. When you encounter issues with anything SSH-related, be sure you've checked your SSH client/server in verbose mode to verify that it is not a PEBCAK issue before seeking technical support from others, and be sure to include your custom values for those options when reporting SSH issues to others so that everyone doesn't waste time trying (uselessly) to repro your issue without them.