OpenSSH keyboard-interactive authentication brute force vulnerability (MaxAuthTries bypass)

Posted by bob on Jul 23, 2015 4:45 PM EDT
kingcopes's blag
Mail this story
Print this story

OpenSSH has a default value of six authentication tries before it will close the connection (the ssh client allows only three password entries per default). With this vulnerability an attacker is able to request as many password prompts limited by the “login graced time” setting, that is set to two minutes by default.

Full Story

  Nav
» Read more about: Story Type: Security

« Return to the newswire homepage

This topic does not have any threads posted yet!

You cannot post until you login.