A Rough Year for SSH
SSH: The Secure Shell, The Definitive Guide January, 2001, ISBN 0-596-00011-1
Ssh Communications Security Resources
Comment on SSH1 timing attacks
Jose Nazario is a biochemistry graduate student nearing the completion of his PhD. Side projects include Linux and other UNIX variants, software and security-related matters, and hobbies outside of his office like fly-fishing and photography.
- « first
- ‹ previous
- 1
- 2
- 3
Today’s modular x86 servers are compute-centric, designed as a least common denominator to support a wide range of IT workloads. Those generic, virtualized IT workloads have much different resource optimization requirements than hyperscale and cloud applications. They have resulted in a “one size fits all” enterprise IT architecture that is not optimized for a specific set of IT workloads, and especially not emerging hyperscale workloads, such as web applications, big data, and object storage. In this report, you will learn how shifting the focus from traditional compute-centric IT architectures to an innovative disaggregated fabric-based architecture can optimize and scale your data center.
Sponsored by AMD
Built-in forensics, incident response, and security with Red Hat Enterprise Linux 6
Every security policy provides guidance and requirements for ensuring adequate protection of information and data, as well as high-level technical and administrative security requirements for a system in a given environment. Traditionally, providing security for a system focuses on the confidentiality of the information on it. However, protecting the data integrity and system and data availability is just as important. For example, when processing United States intelligence information, there are three attributes that require protection: confidentiality, integrity, and availability.
Learn more about catching the bad guy in this free white paper.
Sponsored by DLT Solutions
| Using Salt Stack and Vagrant for Drupal Development | May 20, 2013 |
| Making Linux and Android Get Along (It's Not as Hard as It Sounds) | May 16, 2013 |
| Drupal Is a Framework: Why Everyone Needs to Understand This | May 15, 2013 |
| Home, My Backup Data Center | May 13, 2013 |
| Non-Linux FOSS: Seashore | May 10, 2013 |
| Trying to Tame the Tablet | May 08, 2013 |
- Making Linux and Android Get Along (It's Not as Hard as It Sounds)
- Using Salt Stack and Vagrant for Drupal Development
- New Products
- Validate an E-Mail Address with PHP, the Right Way
- Drupal Is a Framework: Why Everyone Needs to Understand This
- A Topic for Discussion - Open Source Feature-Richness?
- Home, My Backup Data Center
- New Products
- RSS Feeds
- Tech Tip: Really Simple HTTP Server with Python
- Epistle
54 min 48 sec ago - Automatically updating Guest Additions
2 hours 3 min ago - I like your topic on android
2 hours 49 min ago - Reply to comment | Linux Journal
3 hours 11 min ago - This is the easiest tutorial
9 hours 25 min ago - Ahh, the Koolaid.
15 hours 4 min ago - git-annex assistant
21 hours 3 min ago - direct cable connection
21 hours 26 min ago - Agreed on AirDroid. With my
21 hours 36 min ago - I just learned this
21 hours 40 min ago
Enter to Win an Adafruit Prototyping Pi Plate Kit for Raspberry Pi

It's Raspberry Pi month at Linux Journal. Each week in May, Adafruit will be giving away a Pi-related prize to a lucky, randomly drawn LJ reader. Winners will be announced weekly.
Fill out the fields below to enter to win this week's prize-- a Prototyping Pi Plate Kit for Raspberry Pi.
Congratulations to our winners so far:
- 5-8-13, Pi Starter Pack: Jack Davis
- 5-15-13, Pi Model B 512MB RAM: Patrick Dunn
- Next winner announced on 5-21-13!
Free Webinar: Linux Backup and Recovery
Most companies incorporate backup procedures for critical data, which can be restored quickly if a loss occurs. However, fewer companies are prepared for catastrophic system failures, in which they lose all data, the entire operating system, applications, settings, patches and more, reducing their system(s) to “bare metal.” After all, before data can be restored to a system, there must be a system to restore it to.
In this one hour webinar, learn how to enhance your existing backup strategies for better disaster recovery preparedness using Storix System Backup Administrator (SBAdmin), a highly flexible bare-metal recovery solution for UNIX and Linux systems.



Comments
Don't ignore lsh !!
Why do you ignore lsh, which is GNU software, covered
by the regular GPL license? It does only support SSH2 since there are security problems inherent in the SSH1 protocol. If you don't have a problem with that, try it out! It is somewhat different to use than Ssh or OpenSSH, but well worth it.
The latest version can be donwloaded from http://www.lysator.liu.se/~nisse/archive/
and is today 1.3.6
How many security holes has lsh had this year? None. (AFAIK, I'm just a user)
Re: Don't ignore lsh !!
Why? Licence bigotry does nothing to advance either security or Free software. The whole BSD vs GPL holy war results in far too much brainpower being wasted on unnecessary duplication of effort. The fact that no vulnerabilities have been found in Ish does not demonstrate that it is bug-free; it means that it's an unknown quantity. The fact that OpenSSH has had holes discovered (and plugged!) helps demonstrate it's maturity and gives concrete proof of it's ability to survive real-world attack scenerios. It would be foolish to rely on unknown and unproven software in a mission-critical role.
Re: Don't ignore lsh !!
A note from the lsh home page:
LSH IS A WORK IN PROGRESS. IT WILL NOT PROVIDE ANY SECURITY ON SYSTEMS THAT LACK /dev/random. THERE MAY BE OTHER SERIOUS BUGS THAT MAKE IT TOTALLY INSECURE.
You may not want to depend on lsh just yet...
Re: A Rough Year for SSH
Informative article.
Re: A Rough Year for SSH
I have a GPL'd tool that installs ssh keys at http://www.stearns.org/ssh-keyinstall/ Additionally, I have some tutorials at
http://www.stearns.org/doc/