Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
sharjeel
on Jan 14, 2016
|
parent
|
context
|
favorite
| on:
OpenSSH: client bug CVE-2016-0777
Since this is a client side issue, can this be used to exploit those automated scanners who try to break into your SSH machine?
Stefan-H
on Jan 14, 2016
|
next
[–]
Authenticated scanners that use key auth like Qualys' security appliances could have private keys that are valid across the organization, and if using an affected client version, could leak this information to a malicious system on your network.
dsr_
on Jan 14, 2016
|
prev
[–]
No. The scanners are looking for password-accessible accounts, not keyed accounts. The scanners won't have useful keys, nor listening ssh daemons.
Consider applying for YC's Summer 2025 batch! Applications are open till May 13
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: