RE: [VulnDiscuss] Re: iDEFENSE Security Advisory 01.28.03: SSH2 Clients Insecurely Store Passwords

Michal Zalewski <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general
Message-ID <[email protected]>
On Thu, 30 Jan 2003, David Endler wrote:

> Non issue? Even though it's a low severity risk, isn't it plausible that
> memory containing this sensitive information gets swapped to disk?

And how does scrubbing the memory alone prevent this? It does not.
Scrubbing the memory does not prevent any attack vector from being
exercised, it only shrinks the window of opportunity, but it's irrelevant
in most real-world scenarios anyway.

The only way to prevent this is to lock some pages, and this is not
available on all OSes, on others, root privileges are required - and even
then, it's possible to circumvent this protection scheme. On a side note,
this still does not prevent the information from being retained in
kernel-space circular buffers and queues.

-- 
------------------------- bash$ :(){ :|:&};: --
 Michal Zalewski * [http://lcamtuf.coredump.cx]
    Did you know that clones never use mirrors?
--------------------------- 2003-01-30 11:05 --
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.