Mailing List Archive

Weak ssh keys
Hi All,

Is anyone working on a test for the weak debian/ubuntu ssh keys
yet? It would be a simple modification to ssh_proto_version.nasl
to store the fingerprint in the knowledge base, and another
simple plugin to see if it's in the blacklist.

Cheers

Rich.
--
Richard Moore, Principal Software Engineer,
Westpoint Ltd,
Albion Wharf, 19 Albion Street, Manchester, M1 5LN, England
Tel: +44 161 237 1028
Fax: +44 161 237 1031
_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers
Re: Weak ssh keys [ In reply to ]
Hi Richard,

On May 14, 2008, at 1:00 PM, Richard Moore wrote:

> Hi All,
>
> Is anyone working on a test for the weak debian/ubuntu ssh keys
> yet? It would be a simple modification to ssh_proto_version.nasl
> to store the fingerprint in the knowledge base, and another
> simple plugin to see if it's in the blacklist.


We're working on this and should have a plugin soon,



-- Renaud
_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers
Re: Weak ssh keys [ In reply to ]
Renaud Deraison wrote:
> We're working on this and should have a plugin soon,

Great, thanks Renaud.

Rich.
--
Richard Moore, Principal Software Engineer,
Westpoint Ltd,
Albion Wharf, 19 Albion Street, Manchester, M1 5LN, England
Tel: +44 161 237 1028
Fax: +44 161 237 1031
_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers
Re: Weak ssh keys [ In reply to ]
Quick followup : plugin#32314 has been pushed into the plugin feed and
checks for weak RSA/DSA SSH keys.


Have a good day,

-- Renaud


On May 14, 2008, at 3:03 PM, Renaud Deraison wrote:

>
>
> Hi Richard,
>
> On May 14, 2008, at 1:00 PM, Richard Moore wrote:
>
>> Hi All,
>>
>> Is anyone working on a test for the weak debian/ubuntu ssh keys
>> yet? It would be a simple modification to ssh_proto_version.nasl
>> to store the fingerprint in the knowledge base, and another
>> simple plugin to see if it's in the blacklist.
>
>
> We're working on this and should have a plugin soon,
>
>
>
> -- Renaud
> _______________________________________________
> Plugins-writers mailing list
> Plugins-writers@list.nessus.org
> http://mail.nessus.org/mailman/listinfo/plugins-writers
>

_______________________________________________
Plugins-writers mailing list
Plugins-writers@list.nessus.org
http://mail.nessus.org/mailman/listinfo/plugins-writers