LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices


Reply
  Search this Thread
Old 01-19-2017, 12:41 PM   #1
atelszewski
Member
 
Registered: Aug 2007
Distribution: Slackware
Posts: 948

Rep: Reputation: Disabled
Request for checking non typical SSH server authentication method


Hi,

I hope it's not against forum rules, at least it's not strict double posting ;-)
Could you please have a look at Verifying host authenticity (SSH) after logging in, over then accessible secure serial terminal thread and comment?
One note, it's not necessarily about serial terminal any more.

I'm asking here, because I know we have some smart people here that might not browse other categories.

Thanks in advance!

--
Best regards,
Andrzej Telszewski
 
Old 01-19-2017, 01:37 PM   #2
lazardo
Member
 
Registered: Feb 2010
Location: SD Bay Area
Posts: 270

Rep: Reputation: Disabled
I assume you've reproduced with current ssh/ssl?
 
Old 01-19-2017, 01:43 PM   #3
atelszewski
Member
 
Registered: Aug 2007
Distribution: Slackware
Posts: 948

Original Poster
Rep: Reputation: Disabled
Hi,

Quote:
Originally Posted by lazardo View Post
I assume you've reproduced with current ssh/ssl?
What do you mean? What was I about to reproduce?

--
Best regards,
Andrzej Telszewski
 
Old 01-19-2017, 02:40 PM   #4
lazardo
Member
 
Registered: Feb 2010
Location: SD Bay Area
Posts: 270

Rep: Reputation: Disabled
Is the MITM vector still valid after 6 years of ssh/ssl changes? If I'm decrypting real time, can I not see the cat also?

Cheers,
 
Old 01-19-2017, 03:34 PM   #5
atelszewski
Member
 
Registered: Aug 2007
Distribution: Slackware
Posts: 948

Original Poster
Rep: Reputation: Disabled
Hi,
Quote:
Originally Posted by lazardo View Post
Is the MITM vector still valid after 6 years of ssh/ssl changes?
That would require some investigation.
I haven't paid attention to the article date.
But I assume if it wasn't possible then, it's not possible now ;-)
Quote:
Originally Posted by lazardo View Post
If I'm decrypting real time, can I not see the cat also?
Based on the article, I understand that the attacker is not able to be in the middle between you and the real server.
He is simply not able to reuse your private key information, i.e. he allows you to connect to the fake server, but he cannot read the private key details required to connect him to the real server and be in the middle.
But he is still able to read all the traffic, including passwords.
He can also return whichever data he likes.

Now, if I know some secret on the real machine and I execute cat and I read the expected value, I know it's the real machine, because there cannot be anybody in the middle knowing the secret.
But if I read something else or the secret does not exist (e.g. the file does not exist) then I know I'm connected to the attacker's server.

Now, am I correct in my thinking?

--
Best regards,
Andrzej Telszewski
 
Old 02-07-2017, 05:05 AM   #6
atelszewski
Member
 
Registered: Aug 2007
Distribution: Slackware
Posts: 948

Original Poster
Rep: Reputation: Disabled
Hi,

Satisfactory answers have been posted in the original thread.
Marking this one as solved.

--
Best regards,
Andrzej Telszewski
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Transparent squid proxy server and a user authentication method for it. sarveshchandra Linux - Server 0 02-07-2015 07:45 AM
Irregular connections / request for authentication on open Samba server with Windows7 kleptophobiac Linux - Server 1 09-22-2009 04:50 AM
Gaim: Server does not use any supported authentication method nazarioz Linux - Software 8 08-25-2006 04:21 PM
Gaim+GTALK: Server does not use support any authentication method introuble Slackware 6 07-23-2006 04:33 PM
ssh server request k1ll3r_x Linux - Networking 4 04-20-2005 03:27 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware

All times are GMT -5. The time now is 02:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration