Subject: Re: telnet and remote login
To: Greywolf <greywolf@starwolf.com>
From: Tobias Anderberg <tobias.anderberg@axis.com>
List: port-i386
Date: 03/14/2001 09:15:09
Greywolf wrote:

> Personally, I like working in an environment where we can get our
> work done (security pundits be damned); we used to restrict it when we were
> back at rsh, but ssh is a different matter.

One shouldn't rely 100% on that ssh/sshd is safe. Vulnerabilities has
been found in earlier versions of sshd, wich in conjunction with a
vulnerability in rsaref2 allowed an intruder to execute arbitrary
code. And that's just one example.

Though as a protection against password sniffing and the like, I guess
it's pretty safe. At least is't safer than telnet! :-)

/tobba