Ink brush drawing by David Mack

About Matt

Matt Neely a penetration tester and security researcher located in the Cleveland Ohio area.

Learn more here.

Search
Powered by Squarespace
« Knitting Project to Protect Your Privacy | Main | Let the Brute Forcing Begin - Vulnerable SSH Keys Publicly Released »
Thursday
15May2008

Tool Released to Brute Force Vulnerable SSH Server

Earlier this week I posted about a vulnerability in OpenSSL that limits the entropy used to generate encryption keys. Yesterday HD Moore released all possible 1024-bit DSA and 2048-bit RSA keys that could be generated by systems running the vulnerable version of OpenSSL.

Today Markus Mueller released a Perl script that uses these pre-generated keys to brute force public key authentication on SSH servers using vulnerable keys. Markus estimates the maximum amount of time required for the attack is 20 minutes. Of course this assumes account lockout settings do not get in the way and lockout the account.

Again patch your systems and be sure to regenerate your keys!

Cheers,
Matt

Reader Comments

There are no comments for this journal entry. To create a new comment, use the form below.

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>