Full Disclosure mailing list archives
Re: PuTTY private key passphrase stealing attack
From: Marsh Ray <marsh () extendedsubset com>
Date: Wed, 02 Jun 2010 15:50:41 -0500
On 6/2/2010 2:58 PM, paul.szabo () sydney edu au wrote:
... someone with access to a single account could use this to gain the password for that account, and hence possibly sudo access.Oh yes, someone with access to an account has... access to that. If he wanted sudo, then just have a fake sudo: one that traps the password and runs the real sudo after; or one that runs the real sudo but prepending the "bad" command.
Which is an argument against having sudo ask for the password at all: users are expected to type in their password to any command prompt or dialog box that asks for it. Even when the app is legitimate, it still exposes the plaintext password to a much greater stack of software. This is something Vista got right: UAC is a darned secure way to type in your password (but not much else). Once the attacker has the plaintext credentials, he can return at a later time or take those creds to other systems. E.g. certain directory systems effectively require the same password to be valid on every machine in the domain/realm. Some common VPN protocols allow an attacker who obtains the password to decrypt your captured traffic retro-actively. This may expand the scope of the breach considerably. IMHO password expiration policies don't help much. How does forcing users to make new passwords every 30 days help against an attacker who only needs the credentials for milliseconds? - Marsh _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- Re: PuTTY private key passphrase stealing attack halfdog (Jun 01)
- <Possible follow-ups>
- Re: PuTTY private key passphrase stealing attack Benji (Jun 01)
- Re: PuTTY private key passphrase stealing attack Joachim Schipper (Jun 01)
- Re: PuTTY private key passphrase stealing attack Borja Marcos (Jun 01)
- Re: PuTTY private key passphrase stealing attack rapper crazy (Jun 02)
- Re: PuTTY private key passphrase stealing attack Joachim Schipper (Jun 02)
- Re: PuTTY private key passphrase stealing attack paul . szabo (Jun 02)
- Re: PuTTY private key passphrase stealing attack Marsh Ray (Jun 02)
- Re: PuTTY private key passphrase stealing attack Jan Schejbal (Jun 03)
- Re: PuTTY private key passphrase stealing attack Joachim Schipper (Jun 02)