Re: Patching a SSH 'Weakness'

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Hari <innomotive@...>
Cc: <neffk@...>, <misc@...>
Date: Wednesday, September 10, 2008 - 10:21 pm

On Thu, Sep 11, 2008 at 10:06:27AM +0900, Hari wrote:

I remember reading that or a similar paper a while back. The idea has
been around for longer. Is it a weakness? Yes, I'd say so. I can't
comment on how serious it is, but at first blush not too serious. Making
OpenSSH immune would be nice, as a proactive step.

The reason why I think it's a weakness is that you can gather statistics
on typing and use those to infer things. I.e., you can extract
meaningful information from the encrypted session. If you're snooping on
ssh and see a short burst of typing followed by another ssh session from
the remote machine you can guess they typed 'ssh host.example.com' by
the length of typing and the host connected to. Nice crib. Oh, after
than connect was there another short burst? Probably the password. How
many keystrokes can probably be inferred. Perhaps stats on interkey
timing can be used to make some intelligent guesses, such as the 4th
char is NOT punctuation because is followed char 3 too closely. Or
whatever.

Just because this takes real work and isn't in a popular script kiddie
tool doesn't mean you should discount it. Traffic analysis of one kind
or another has a long history of paying off well.

--
Darrin Chandler | Phoenix BSD User Group | MetaBUG
dwchandler@stilyagin.com | http://phxbug.org/ | http://metabug.org/
http://www.stilyagin.com/ | Daemons in the Desert | Global BUG
Federation

[demime 1.01d removed an attachment of type application/pgp-signature]

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Patching a SSH 'Weakness', Kevin Neff, (Wed Sep 10, 3:58 pm)
Re: Patching a SSH 'Weakness', Mike M, (Fri Sep 12, 8:01 am)
Re: Patching a SSH 'Weakness', Kevin Neff, (Fri Sep 12, 10:02 am)
Re: Patching a SSH 'Weakness', johan beisser, (Fri Sep 12, 5:32 pm)
Re: Patching a SSH 'Weakness', STeve Andre', (Wed Sep 10, 10:56 pm)
Re: Patching a SSH 'Weakness', Giancarlo Razzolini, (Thu Sep 11, 11:06 am)
Re: Patching a SSH 'Weakness', Damien Miller, (Thu Sep 11, 2:28 am)
Re: Patching a SSH 'Weakness', STeve Andre', (Thu Sep 11, 8:50 am)
Re: Patching a SSH 'Weakness', Aaron Glenn, (Thu Sep 11, 12:40 am)
Re: Patching a SSH 'Weakness', Johan Beisser, (Thu Sep 11, 1:35 am)
Re: Patching a SSH 'Weakness', Hari, (Wed Sep 10, 9:06 pm)
Re: Patching a SSH 'Weakness', Paul de Weerd, (Thu Sep 11, 4:49 am)
Re: Patching a SSH 'Weakness', Darrin Chandler, (Wed Sep 10, 10:21 pm)
Re: Patching a SSH 'Weakness', Marco Peereboom, (Wed Sep 10, 9:50 pm)
Re: Patching a SSH 'Weakness', Damien Miller, (Wed Sep 10, 8:59 pm)