Researchers develop SSH cracker

Secure Shell compromised by password cracking program.

Written by James Middleton

Researchers at the University of California at Berkeley have discovered more vulnerabilities in Secure Shell (SSH) which allow an attacker to learn significant information about what data is being transferred in SSH sessions, including passwords.

SSH was designed as a secure channel between two machines, based on strong encryption and authentication. But by observing the rhythm of keystrokes, and using advanced statistical techniques on timing information collected, attackers can pick up significant details.

Each keystroke from a user is immediately sent to the target machine as a separate IP packet. By performing a statistical study on a user's typing patterns, and applying a key sequence prediction algorithm, the researchers managed to successfully predict key sequences from inter-keystroke timings.

A password cracker program, dubbed Herbivore, was developed on the back of the research. Herbivore is capable of learning a user's password by monitoring SSH sessions.

"Unfortunately, SSH is not as bullet proof as one would hope. Our attack shows that an eavesdropper can learn sensitive information about a user's data, such as passwords, over SSH," said Dawn Xiaodong Song, one of the researchers.

Another vulnerability allowing remote access to SSH accounts with two character passwords was also discovered last week.

A white paper, entitled Timing Analysis of Keystrokes and Timing Attacks on SSH, is available here.

Tags:

Further reading

'Limpninja' Trojan horse emerges

Hackers make ninja-style swoop on Linux boxes   More...

SSH flaw puts Unix users on alert

Secure Shell encryption protocol at risk, users warned.   More...

Related articles

Hackers eye open source coding tools

Security firm warns of 'cross-build injection vulnerability'   More...

China accused of Trojan onslaught

Trail leads back to China-based operations including a government website   More...

Silicon nanowires turn heat into power

Berkeley boffins claim thermoelectric breakthrough   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement