Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Another example - where OpenSSH itself was not to blame, but rather PAM - was the old https://www.debian.org/security/2002/dsa-177

Where locked accounts were treated as password-less accounts, and would allow direct ssh access.

In Debian's defence, this was caught in the unstable distro and never made it out to a stable release.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: