Re: User enumeration in Dropbear 2018.76 and earlier

2018-08-20 Thread Matt Johnston
On Mon 20/8/2018, at 5:50 pm, Matthijs R. Koot wrote: > > The user enumeration issue in OpenSSH [0] also exists in Dropbear 2018.76 > and earlier; at least going back to w/v2013.58 (didn't test with earlier > versions yet). It is specifically related to this code in svr-auth.c [1]: > [0]

User enumeration in Dropbear 2018.76 and earlier

2018-08-20 Thread Matthijs R. Koot
Hi all, The user enumeration issue in OpenSSH [0] also exists in Dropbear 2018.76 and earlier; at least going back to w/v2013.58 (didn't test with earlier versions yet). It is specifically related to this code in svr-auth.c [1]: - 8< - 8< - 8< - 8< - #if