Bug in OpenSSH Linux allows password cracking – A simple but extremely important vulnerability has been found in the widely used OpenSSH software, allowing attackers to try thousands of login password combinations per connection in a short period of time.
OpenSSH is the most well-known software widely used for remote access to Linux-based systems. Generally, the software allows 3 to 6 password login attempts before blocking the connection, but a new vulnerability allows attackers to make thousands of authentication requests.
OpenSSH servers with keyboard-interactive authentication enabled, including FreeBSD Linux, can be exploited to carry out an attack on the OpenSSH protocol, a security researcher from KingCope explains in a blog post.

Hackers could exploit this vulnerability because keyboard-interactive authentication is enabled by default on most systems.
The researcher also published a proof-of-concept exploit code, which is simply a command, like the following:
ssh -lusername -oKbdInteractiveDevices=`perl -e 'print “pam,” x 10000'` targethost
This simple command effectively allows over 10,000 password entry attempts within two minutes of the first login attempt.
Although it depends on the connection and the victim's Linux machine, the two minutes of 'grace period' and thousands of connection attempts are enough to achieve a connection using a dictionary along with the list of the most widely used passwords.
The vulnerability is found in the latest OpenSSH version, which is 6.9.
How can I prevent the attack?
Administrators advise that users follow the following until the new patched version of OpenSSH is released:
· Use an encrypted key pair that is at least 2,048 Bits in length
· Always use a strong password to protect your Private Key
· Reduce the grace period to 20 to 30 seconds.
· Use Fail2Ban or Pam-Shield to reduce failed login attempts.
