Updates close 19-year-old security hole in remote tool OpenSSH
Summary
In 2018 Qualys reported a hole in OpenSSH (CVE-2018-15473) that had existed since the first version in 1999. With prepared packets, attackers could check remotely whether a user name exists, because the server ended the connection differently for valid names. The hole was not considered critical but provided material for targeted password attacks.
Ideas
- Different behaviour for valid and invalid names gives away user accounts.
- Known user names make brute-force attacks more efficient.
- Proof-of-concept code was already circulating at the time of publication.
- Because OpenSSH is so widespread, comprehensive updates are hardly achievable.
Insights
- Even small information leaks become building blocks of larger attacks.
- The security of SSH depends more on the login method than on keeping names secret.
Facts
- Sekurak had reported the hole to the OpenSSH developers even before Qualys.
- All OpenSSH versions since 1999 were affected.
References
Critique
- The package versions named come from one distribution and leave open which upstream version is fixed.
Recommendations
- Only allow SSH login by key and disable password login.
- Limit login attempts, for example with fail2ban or firewall rules.
Links to the original source and the Web Archive open in a new tab.