[ILUG] SSH dictionary attacks.

paul at clubi.ie paul at clubi.ie
Wed Aug 23 21:08:53 IST 2006


On Wed, 23 Aug 2006, Aine Douglas wrote:

> What makes you think that a passphrase, however random, made to those
> specs wouldn't correspond to a korean dictionary entry?

You're right: SSH is utterly vulnerable to attack by monkeys 
randomly guessing your pass-phrase and/or secret key. Do you want to 
write up the email to Bugtraq or shall I? :)

I dub it the "lucky monkey" security problem..

regards,
-- 
Paul Jakma	paul at clubi.ie	paul at jakma.org	Key ID: 64A2FF6A
Fortune:
I have often regretted my speech, never my silence.
 		-- Publilius Syrus



More information about the ILUG mailing list