3 ms·
Another example - where OpenSSH itself was not to blame, but rather PAM - was the old https://www.debian.org/security/2002/dsa-177 https://www.debian.org/securi
by 0x0 4y ago
Another example - where OpenSSH itself was not to blame, but rather PAM - was the old https://www.debian.org/security/2002/dsa-177 https://www.debian.org/security/2002/dsa-177
Where locked accounts were treated as password-less accounts, and would allow direct ssh access.
In Debian's defence, this was caught in the unstable distro and never made it out to a stable release.