Linux Today: Linux News On Internet Time.
Search Linux Today
search.internet.com
Linux News Sections:  Blog -  Developer -  High Performance -  Infrastructure -  IT Management -  Security -  Storage -
Linux Today Navigation
LT Home
Preferences
Contribute
Link to Us
Search
Linux Jobs

Become a Marketplace Partner

internet.commerce
Be a Commerce Partner














The Linux Channel at internet.com
Linux Today
Enterprise Linux Today
Apache Today
JustLinux.com
Linux Planet
PHPBuilder
All Linux Devices
Technology Jobs

JustTechJobs.com

LinuxToday Newsletters
Subscribe News
Subscribe PR
Subscribe Security

internet.com
IT
Developer
Internet News
Small Business
Personal Technology

Search internet.com
Advertise
Corporate Info
Newsletters
Tech Jobs
E-mail Offers

 






Current Newswire:

Best Linux Distributions of the Decade (2000-2009)

The iPad questions Apple won't answer

HP Launches First Quad-Core Itanium Systems

Dell Ubuntu Order Experience

Power Up Linux GUI Apps

Ksplice debuts zero downtime service for Linux

BM Ups Its Processor Power to 7

KDE.org Relaunched for Software Compilation 4.4

The application is the new the operating system

Linux can compete with the iPad on price, but where’s the magic?




Systems Engineer Sr – Automation – Opsware SAS / HP SA
Next Step Systems
US-TX-Houston

Justtechjobs.com Post A Job | Post A Resume
:Debian SSH Key-Cracking Tools Released, Tips for Tightening
Debian SSH Key-Cracking Tools Released, Tips for Tightening
May 16, 2008, 12 :45 UTC (5 Talkback[s]) (7940 reads)

Computerworld: Tools Circulate that Crack Debian, Ubuntu Keys

"A recently disclosed vulnerability in widely used Linux distributions can be exploited by attackers to guess cryptographic keys, possibly leading to the forgery of digital signatures and theft of confidential information, a noted security researcher said today.

"HD Moore, best known as the exploit researcher who created the Metasploit penetration testing framework, called the vulnerability in Debian and Ubuntu systems 'ugly' and said it will be a big job for administrators to find every flawed key, then reissue them..."

Complete Story

Computerworld Australia: How to Avoid the Debian SSH Key Attacks

"This means that there are only 32,767 possible keys for each key length and there are a number of resources starting to appear that are targeting the weak key issue. One of the tools, developed by Markus Mueller, claims to defeat a 2048 bit RSA SSH key in less than 20 minutes.

"HD Moore, the founder of Metasploit, points out that there are several features of Debian that make the process of brute forcing a key even simpler, given that a lot of Debian systems use sequential pid allocation and most keys are likely to have been user generated with a pid between 500 and 10,000 (which effectively reduces the keyspace to 9,500 keys)..."

Complete Story

Related Stories:
Vendors Are Bad For Security(May 13, 2008)
Disk Encryption Easily Cracked, Researchers Find(Feb 22, 2008)


Index Mode   |   Flat Mode   |   Thread Mode   |   Thread Flat  
  Talkback(s) Name  and Date
>> The flaw was the removal of most of t ...   It's never too late to switch to Linux and ope   
Jose_X
May 16, 2008, 20:22:24
 
>> Does anyone know the details? I am po ...   Re: It's never too late to switch to Linux and   
Jose_X
May 16, 2008, 20:42:09
 
The problem is debian (and Ubuntu/Kbuntu ...   The problem   
Micheas
May 16, 2008, 20:46:06
 
Thanks for the update, and this too http ...   Re: The problem   
Jose_X
May 16, 2008, 21:48:33
 
Here:http://svn.debian.org/viewsvn/pkg-o ...   The bad code   
jhansonxi
May 17, 2008, 00:36:01
 
  Home | Search Talkbacks | Customize View    Top of Page  



Enter your comments below:

* Your Name:

* Your Email Address:

* Subject:

CC: [will also send this talkback to an E-Mail address]

* Comments:

Tags allowed:<I>,<B> and <U>. See our talkback-policy for more about talkback content.

Fields marked with * are required!






..............................




All times are recorded in UTC.
Linux is a trademark of Linus Torvalds.
Powered by Linux, Apache and PHP


The Network for Technology Professionals

Search:

About Internet.com

Legal Notices, Licensing, Permissions, Privacy Policy.
Advertise | Newsletters | E-mail Offers