Quantcast
Channel: OpenSSH keyboard-interactive authentication brute force vulnerability (MaxAuthTries bypass) : netsec
Viewing all articles
Browse latest Browse all 27

/u/dRiek on OpenSSH keyboard-interactive authentication brute force vulnerability (MaxAuthTries bypass)

$
0
0

Tried an OSX target, worked. Not sure what the defaults for sshd_config are on OSX though, don't run it myself. What's problematic for OSX is that there is almost no timeout between failed password attempts, as you see in most Linux distros. This increases the possible attack speed dramatically.


Viewing all articles
Browse latest Browse all 27

Trending Articles