this post was submitted on 01 Jul 2024
242 points (98.8% liked)

Linux

5409 readers
124 users here now

A community for everything relating to the linux operating system

Also check out [email protected]

Original icon base courtesy of [email protected] and The GIMP

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 37 points 5 months ago (1 children)

If I'm not mistaken, it seems like this is a timing attack and you need a lot of attack attempts to make it work. If you have like a fail2ban rule for ssh it should mitigate this attack to quite some degree, right? (Of course updating would still be the best).

[–] [email protected] 12 points 5 months ago (1 children)

While statistically unlikely, it would be possible to exploit the vulnerability on the first attempt

[–] [email protected] 4 points 5 months ago