[VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords
Dragos Ruiu <[email protected]>
| Newsgroups | gmane.comp.security.vulnerabilities.watch.general |
|---|---|
| Organization | all terrain ninjas |
| Message-ID | <[email protected]> |
On January 29, 2003 05:51 pm, iDEFENSE Labs wrote: > AbsoluteTelnet, SecureCRT, Entunnel, SecureFx, and PuTTY do not properly > scrub memory allowing an attacker with access to memory or a memory dump > to retrieve authentication information. If they have access to your raw mem... you've got bigger issues than this. Many other avenues exist to said credentials no matter what Putty et al do... Non-issue. -- [email protected] pgp: http://dragos.com/ kyxpgp http://cansecwest.com