OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: itojuniijlab.net
Date: Mon Jul 01 2002 - 08:52:58 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    >> i guess the problem is not how many users are using s/key, but how many
    >> of installed systems that has it turned on (most of the openssh
    >> installation shipped with it turned on).
    >Yes, I realize virtually all OpenSSH users were vulnerable.
    >However, how could not publishing valid workaround help with that?

            i recommend you to read section 6 (release process) of
            http://openssh.com/txt/preauth.adv

    itojun