[Bug 3439] identify password prompts

bugzilla-daemon at mindrot.org bugzilla-daemon at mindrot.org
Sat Apr 15 08:07:15 AEST 2023


https://bugzilla.mindrot.org/show_bug.cgi?id=3439

--- Comment #4 from tar.ancalime.numenor at gmail.com ---
Hey Darren.

Just one question on this:

In both cases, the prompt with password and the prefix with
keyboard-interactive, are these generated by the ssh client?

Cause if e.g. the server could control the full prompt, a hostile
server could try tricking people into entering passphrases/TOTPs for
another server.

Thanks :-)

-- 
You are receiving this mail because:
You are watching someone on the CC list of the bug.
You are watching the assignee of the bug.


More information about the openssh-bugs mailing list