On Sep 12, 2008, at 7:02 AM, Kevin Neff wrote:
> Thanks for all the comments. I think we're all pretty much on the
Sorry, I'm finally at my real mail client. It's not a "real"
vulnerability, imho. Merely a way to time and attack the individual
keystrokes. I suspect you could ID individual users, if not figure out
passwords, etc.
If you're that concerned about your ssh session, multiplex the tunnel
and have an expect script randomly execute remote commands through it.
Your interactive shell will be the "real" session, with expect
throwing interactive "noise." No real additional setup required, just
using multiplexed tunneling in ssh(1)
| hooanon05 | [PATCH 67/67] merge aufs |
| Greg Kroah-Hartman | [PATCH 008/196] Chinese: add translation of volatile-considered-harmful.txt |
| monstr | [PATCH 33/52] [microblaze] bug headers files |
| Oliver Pinter | Re: x86: 4kstacks default |
git: | |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 15/37] dccp: Set per-connection CCIDs via socket options |
| David Miller | [GIT]: Networking |
| Natalie Protasevich | [BUG] New Kernel Bugs |
