possible bug

Jirka Zajpt jirka at zajpt.cz
Fri Jul 5 07:46:18 EST 2002


  I checked that on 5 machines, platforms were openbsd3.0 and red hat 
linux 7.2-7.3. And configuration was default in most cases.

Jirka Zajpt, <jirka at zajpt.cz>

Ben Lindstrom wrote:

>Platform, configuration, etc would be a useful thing.
>
>On Thu, 4 Jul 2002, Jirka Zajpt wrote:
>
>  
>
>>I don't know if that what I found is real bug, but I think that it's
>>important.
>>
>>When you give a valid user at login, openssh waits something about 3
>>seconds after giving password (I'am not sure if its depends on system
>>configuration). But when you give user which does not exist, openssh
>>does not wait the same time. This allows to detect valid user on a
>>target system.
>>
>>Jirka Zajpt, <jirka at zajpt.cz>
>>
>>_______________________________________________
>>openssh-unix-dev at mindrot.org mailing list
>>http://www.mindrot.org/mailman/listinfo/openssh-unix-dev
>>
>>    
>>
>
>
>.
>
>  
>






More information about the openssh-unix-dev mailing list