Re: ? Unsafe terminal escape sequences and ANSI codes from decryption

[email protected] (Scott Dorsey) 8 Mar 2023 20:56:30 -0000
Newsgroups sci.crypt,alt.security.pgp,alt.bbs,comp.terminals,alt.computer.security
Organization Former users of Netcom shell (1989-2000)
Message-ID <[email protected]>
Grant Taylor  <[email protected]> wrote:
>On 3/6/23 7:22 PM, Scott Dorsey wrote:
>
>> There also was a thing on the CDC 721 terminal where you could send a 
>> sequence to copy the scrollback buffer into a second screen memory, 
>> so after the person cleared the terminal you could go back and see 
>> their session text including the login password by going through 
>> menus to display the buffer.  A friend of mine used this to great 
>> effect at the registration office when he was a student.
>
>Interesting.
>
>It seems like both of these attacks could relatively easily be defended 
>against -- as long as you knew to do so -- in that you could re-program 
>the terminal to behave correctly /and/ to clear the second screen memory.

Yes.  The CDC 721 attack required physical access to the terminal and it
required the terminal to remain powered on before the attacker got to it.
Which is typically easy in an open terminal cluster but could be defeated
by turning the terminal off after using it.

>For a few minutes I thought you were going to suggest something to have 
>the terminal copy screen contents and feed it back to the host in a way 
>that didn't echo on the host.

There might be a way to do that, I don't know.  The HP terminals have so
many crazy modes for local forms management and multidrop connections and
so forth that there could be all kinds of hidden vulnerabilities in there.

ANSI terminals are so much more sane than some of the stuff we had out there.
--scott
-- 
"C'est un Nagra. C'est suisse, et tres, tres precis."