Spotlight | Reviews | Current Issue | Academy | Newsletter | Subscribe | Shop |
Departments

Partner Links
Make your own website
WinWeb OnlineOffice
Comparing prices of hardware is worth it.
Price Comparison
UK Linux Jobs
What:
Where:
Country:
vacatures Netherlands njobs Linux vacatures
arbeit Deutschland njobs Linux arbeit
work United Kingdom njobs Linux jobs
Lavoro Italia njobs Linux lavoro
Emploi France njobs Linux emploi
trabajo Espana njobs Linux trabajo

user friendly

Admin Magazine

ADMIN Network & Security

Subscribe now and save!

ADMIN - Explore the new world of system administration! Special introductory offer! Order by September 30th to save 10% off the regular subscription price! Each issue delivers technical solutions to the real-world problems you face every day. Learn the latest techniques for better:

  • network security
  • system management
  • troubleshooting
  • performance tuning
  • virtualization
  • cloud computing

 

on Windows, Linux, Solaris, and popular varieties of Unix.

http://www.admin-magazine.com/

  linux-magazine.com » Online » News » OpenSSH 5.2 Secured and Tuned  

Print this page. Recommend
Share

OpenSSH 5.2 Secured and Tuned

Even though the OpenSSH project emphasizes that the focus of 5.2 is bug fixes to the 5.1 version, 5.2 does contain some notable enhancements.

Security-wise the new OpenSSH version replaces cipher block chaining (CBC) mode as the default cipher order with the Advanced Encryption Standard (AES) Counter (CTR) mode to remove the susceptibility to "Plaintext Recovery Attack Against SSH." The software also adds other countermeasures to these attacks, as reported in CPNI Vulnerability Advisory SSH 957037. Last November it became clear that many versions of OpenSSH exposed up to 32 bits of plaintext ciphertext to attackers when the default CBC mode was in use. The solution in 5.2 was to read the maximum supported packet length instead of terminating the connection, thereby eliminating the leaks that allowed the plaintext recovery attacks.

Compared to OpenSSH 5.1, the updated version provides further command line options and minor functional enhancements. For example, the ssh -y option redirects logging to syslog and dynamic port forwarding was improved. The release changelog includes the list of fixed bugs.

OpenSSH emanates from the OpenBSD project, where a separate team focuses on OpenSSH's portability to different systems. The mirrors with the portable versions also include diffs against the OpenBSD source.

(Anika Kehrer)

Comments


Print this page. Recommend
Share
Related Articles
OpenSSH 5.4 Disables SSH Protocol 1
OpenSSH 5.6 Released into the Wild
CeBIT 2009: OpenStreetMap Wins Two Linux New Media Awards
(Update:) Fedora: Chronicle of a Server Break-in
Hacker Group to Release OpenSSH Exploit and Worm: "Give us 48 Hours"
OpenBSD Developers Work on AerieBSD
Get your backstage pass to Linux!

If you're ready for a deeper look, Linux Magazine gives you a view behind the scenes.

Don't miss out on the tools, tutorials, and reviews you'll need to unlock the secrets of Linux.

more...