Security Incidents mailing list archives

Re: Attacks against SSH?


From: Przemyslaw Frasunek <venglin () freebsd lublin pl>
Date: Wed, 5 Dec 2001 07:11:57 +0100

On Wednesday 05 December 2001 03:51, Russell Fulton wrote:
package with SSH-1.5-OpenSSH-1.2.3 in not vulnerable:
bluebottle:~ >ssh -l`perl -e '{print "A"x90000}'` 130.216.yyy.xxx
Word too long.

No, it doesn't mean you're not vulnerable. Some shells (csh, tcsh) limits 
argument length and prints 'Word too long'.

-- 
* Fido: 2:480/124 ** WWW: http://www.frasunek.com/ ** NIC-HDL: PMF9-RIPE *
* Inet: przemyslaw () frasunek com ** PGP: D48684904685DF43EA93AFA13BE170BF *

----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: