[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Experience with lsh-{server|client}?



On Thu, Sep 18, 2003 at 11:51:28AM +0100, Colin Watson wrote:
> On Thu, Sep 18, 2003 at 05:35:48AM -0500, Ron Johnson wrote:
> > There have been so many critical bugs in OpenSSH, I'm looking for
> > something else.
> 
> It's worth remembering that the OpenSSH bugs of the moment are getting
> down to the incredibly picky. As I understand it (which isn't
> completely), the current lot allow you to write some zeroes into an area
> of memory partly of your choosing. Less prominent SSH implementations
> almost certainly have just as many hard-to-find and hard-to-exploit bugs
> but less attention is being paid to them so they haven't been found yet.
Bennett Todd mentioned it on F-D but it also has it's bugs (as he mentioned
a few posts later).
So ATM there doesn't seem to be good alternative.

Sven
-- 
http://www.comboguano.de
http://sven.linux-ist-pleite.de
I'm root, if you see me laughing you better have a backup!



Reply to: