Technology content trusted by users in North America and around the world.
4,961 Articles | 29,968 Posts
Select Your Edition:  
Tweakipedia
A wealth of
tech information!

TRENDING NOW: EA Vice President says PS4 and Xbox One are a generation ahead of the current fastest gaming PC on the market
USA EditionYou are located: Home > All News > News > Flaw in OpenSSH could compromise data

Flaw in OpenSSH could compromise data

By: (more) | Posted: May 20, 2009 1:40 pm

A critical flaw in the OpenSSH standard has been fully disclosed by a team of researchers at the Royal Holloway, University of London.

 

The flaw lays in the ability of an attacker for force certain parts of the encryption sequence into plain text. They can force up to 32 bit of text out into the clear. The chances of this are slim but are still there and represent vulnerability for any highly sensitive information or data.

 

The attack uses flaws in the RFC (request for comment) standard that makes up OpenSSH. This problem was first disclosed in November 2008 but not all the details were made public.

 

The issue can be protected against by using AES in CTR mode instead of CBC (Cipher-Block Chaining Mode). The flaw is open in OpenSSH 4.7, Version 5.2 introduces counter measures against the flaw but does not actually correct the flaw.

 


Read more here.

 

Flaw in OpenSSH could compromise data

 


According to Paterson, a man-in-the-middle attacker could sit on a network and grab blocks of encrypted text as they are sent from client to server. By retransmitting the blocks to the server, an attacker can work out the first four bytes of corresponding plaintext. The attacker can do this by counting how many bytes the attacker sends until the server generates an error message and tears down the connection, then working backward to deduce what was in the OpenSSH encryption field before encryption.

 

The attack relies on flaws in the RFC (Request for Comments) Internet standards that define SSH, said Paterson.

 

Paterson gave a talk on Monday at the IEEE Symposium on Security and Privacy in Oakland, Calif., to explain his group's research findings. The three ISG academics involved in the research were Paterson, Martin Albrecht, and Gaven Watson.

 

Related Tags



Further Reading: Read and find more news at our news index page.

TweakTown News RSS FeedDo you get our news RSS feed? Get It! Got a news tip? Tell Us!

Post a Comment about this news



Check out our
RSS feeds!
  • Upcoming Content: Scythe Mugen 4 Tower CPU Cooler Review
  • Upcoming Content: NZXT Grid 10 Port Fan Hub Review
  • Upcoming Content: MSI Z77A-GD65 Gaming Series (Intel Z77) Motherboard Review
  • Upcoming Content: Western Digital My Passport Edge for Mac 500GB External HDD Review
  • Upcoming Content: PQI Air Card 4GB Wi-Fi SDHC Review
  • Upcoming Content: LaCie CloudBox 1TB Personal NAS Review
  • Upcoming Content: Star Trek: The Next Generation - Season Three (1989) Blu-ray Review
  • Upcoming Content: The Hobbit: An Unexpected Journey (2012) Blu-ray Movie Review
  • Upcoming Content: Whatever happened to Comodo Time Machine?
  • Upcoming Content: ADATA DashDrive Elite UE700 USB 3.0 Flash Drive Review
  • Upcoming Content: MyDigitalSSD BP4 240GB mSATA Review


Tech News Posts

View More News Posts


TweakTown Web Poll

Question: What new stuff are you most excited to see at Computex Taipei 2013?

Cases, Coolers & PSU’s

CPU's

Gadgets

GPU's & Video Cards

Keyboards & Mice

Laptops, Tablets & Phones

Motherboards & Chipsets

New Tech

SSD's & Memory

Booth Babes

or View the Results

View More Polls

Forum Activity

View More Forum Posts

Press Releases

View More Press Releases