Vulnerability Development mailing list archives

Re: ssh


From: Jose Nazario <jose () biocserver BIOC cwru edu>
Date: Wed, 6 Feb 2002 15:49:00 -0500 (EST)

On Wed, 6 Feb 2002, -l0rt- wrote:

Assuming that I use strong passwords, is password auth using ssh2 sshd
3.1.0 considered insecure?

nothing significant, ie nothing more than you would have to worry about
compared to getting rooted through your sshd or other daemons, or a
connection hijack at the network layer.

____________________________
jose nazario                                                 jose () cwru edu
                     PGP: 89 B0 81 DA 5B FD 7E 00  99 C3 B2 CD 48 A0 07 80
                                       PGP key ID 0xFD37F4E5 (pgp.mit.edu)


Current thread: