Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenSSH mild security bug

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    5 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      Harvy66
      last edited by

      http://arstechnica.com/security/2015/07/bug-in-widely-used-openssh-opens-servers-to-password-cracking/

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by

        I don't allow password auth with SSH. ;)

        1 Reply Last reply Reply Quote 0
        • H
          Harvy66
          last edited by

          Even if you did, an online attack that is limited to some small number(tends of thousands) of attempts is meaningless against a strong password. And fail2ban would catch it anyway.

          1 Reply Last reply Reply Quote 0
          • H
            Harvy66
            last edited by

            Turns out the issue isn't OpenSSH, it's PAM, and from the sounds of it, only PAM on FreeBSD, not any Linux distro.

            1 Reply Last reply Reply Quote 0
            • C
              cmb
              last edited by

              It's specific to a configuration that seemingly only FreeBSD uses by default. It's really a non-issue, should disable password logins if you're opened to the Internet, and if your password is guessable in the amount of tries you could get through you're doing it wrong. We dropped the grace time to limit the potential impact in 2.2.4 and newer.  https://redmine.pfsense.org/issues/4875

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.