[VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords

Dragos Ruiu <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Organization all terrain ninjas
Message-ID <[email protected]>
On January 29, 2003 05:51 pm, iDEFENSE Labs wrote:
> AbsoluteTelnet, SecureCRT, Entunnel, SecureFx, and PuTTY do not properly
> scrub memory allowing an attacker with access to memory or a memory dump
> to retrieve authentication information.

If they have access to your raw mem... you've got bigger issues than this.
Many other avenues exist to said credentials no matter what Putty et al do...

Non-issue.

-- 
[email protected]   pgp: http://dragos.com/ kyxpgp
http://cansecwest.com
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.