bk99.de entertain the web since 1997

Updates close 19-year-old security hole in remote tool OpenSSH

Summary

In 2018 Qualys reported a hole in OpenSSH (CVE-2018-15473) that had existed since the first version in 1999. With prepared packets, attackers could check remotely whether a user name exists, because the server ended the connection differently for valid names. The hole was not considered critical but provided material for targeted password attacks.

Ideas

  • Different behaviour for valid and invalid names gives away user accounts.
  • Known user names make brute-force attacks more efficient.
  • Proof-of-concept code was already circulating at the time of publication.
  • Because OpenSSH is so widespread, comprehensive updates are hardly achievable.

Insights

  • Even small information leaks become building blocks of larger attacks.
  • The security of SSH depends more on the login method than on keeping names secret.

Facts

  • Sekurak had reported the hole to the OpenSSH developers even before Qualys.
  • All OpenSSH versions since 1999 were affected.

References

Critique

  • The package versions named come from one distribution and leave open which upstream version is fixed.

Recommendations

  • Only allow SSH login by key and disable password login.
  • Limit login attempts, for example with fail2ban or firewall rules.

Read the original article

Search the Web Archive