3 ms·
So the vast majority of servers is not at risk because OpenSSH is not vulnerable to these attacks?
by fguerraz 3y ago
So the vast majority of servers is not at risk because OpenSSH is not vulnerable to these attacks?
- tptacek 3y agoCorrect. You are almost certainly not at risk. OpenSSL isn't vulnerable to this attack; your stack needs to be seriously archaic to have a vulnerable RSA implementation.
- slt2021 3y agoIndustrial IoT: hold my beer
- fweimer 3y agoSome OpenSSL deployments use RSA plugins that do not contain the check—it's not in generic OpenSSL or OpenSSH code, so every engine plugin needs to implement its own check.
- tptacek 3y agoWhich plugins are you aware of that are used for RSA signatures and don't check signature validity? Just curious, from your comment it seemed like there might be specific ones.