Joshua Penix wrote:
Yes, we could have users with the public half of weak keys in their ~/.ssh/authorized_keys... is there an easy way to check?

Tools and blacklists of the actual keys to compare with can be found here:

http://metasploit.com/users/hdm/tools/debian-openssl/

along with some great humor at the top of the page. Bwahaha...Go Debian! ;)

--
Tracy R Reed                  Read my blog at http://ultraviolet.org
Key fingerprint = D4A8 4860 535C ABF8 BA97  25A6 F4F2 1829 9615 02AD
Non-GPG signed mail gets read only if I can find it among the spam.

--
[email protected]
http://www.kernel-panic.org/cgi-bin/mailman/listinfo/kplug-steer

Reply via email to