HomeSecurityOpenSSL is affected by a bug in user enumeration

OpenSSL is affected by a bug in user enumeration

The popular OpenSSH is affected by a user enumeration bug that could be exploited by a remote attacker to check a list of hacked credentials.

OpenSSL is affected by a bug in user enumeration

A bug (CVE-2016-6210) in the popular OpenSSH cryptography library could be exploited by a remote attacker to enumerate users on systems running SSHD. An attacker could exploit the flaw to check whether usernames are valid, from a server exposed online. The problem exists on most systems where the Blowfish algorithm runs faster than SHA256 / SHA512.

"By sending long passwords, a remote user can enumerate users on systems running SSHD. This problem exists in most modern configurations due to the fact that it takes much longer to compute the SHA256/SHA512 hash than the Blowfish hash," states the Abstract for the OpenSSH.

Unfortunately, the bug still exists in OpenSSH, but according to Verint expert Eddie Harari, who published advice on Full Disclosure, OpenSSH developer Darren Tucker is already working on a fix.

If an attacker attempts to authenticate a user to an OpenSSH server with a user ID and a long, but incorrect password, then the server will respond quickly for fake users, but more slowly for real users.

“When SSHD tries to authenticate a non-existent user, it will get a fake password structure that will be embedded in the SSHD source code. In this structure, the password hash is based on Blowfish ($2) algorithm. If real users' passwords are hashed using SHA256 / SHA512, then sending large passwords (10KB) will lead to a shorter response time from the server for non-existent users.”

It's easy to imagine the possible attack scenarios; a hacker could check a list of compromised credentials on a server running SSHD.

The exploit of the bug was tested in opensshd-7.2p2, but experts speculate that it could also affect earlier versions.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS