OpenSSH daemon security bug?

Michael Stone mstone at mathom.us
Thu Jan 7 00:03:05 EST 2010


On Wed, Jan 06, 2010 at 11:21:27AM +0100, Aris Adamantiadis wrote:
>stealing the password (keypress sniffer, console sniffer, ...) or by
>fetching the decrypted key in the user agent.

Or using ssh-agent directly. A lot of people have those set up so they 
enter the passphrase once and then never again until they logout/reboot.

Mike Stone


More information about the openssh-unix-dev mailing list