Hacker Newsnew | past | comments | ask | show | jobs | submit | jkcunningham's commentslogin

It says it is in SSH 4.7. I just checked and I'm already up to version 5.1. on a 2.6.26-1 system. How dated is this problem?


This is a flaw in the SSH standard itself, not in a specific version of software. Countermeasures have been put in place to mitigate the flaw in OpenSSH however.

"They've fixed [OpenSSH]; they've put countermeasures in place to stop our attack," said Patterson. "But the standard has not changed."


That's how he generates lots of web traffic. Most of his writing is pretty mundane otherwise.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: