Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?
SSHambles: The Laughable Security Gaps You Didn’t Expect
When runZero researchers investigated the xz backdoor, they stumbled upon numerous vulnerabilities in poorly implemented SSH services. “We never found Jia Tan, but we did find tons of long-tail issues in SSH,” said Rob King. Their Black Hat talk details these findings and introduces SSHamble,…

Hot Take:
Well, it turns out even “secure” SSH is more like Swiss Cheese than Fort Knox. Who knew poking protocols could be so revealing?
Key Points:
- runZero researchers discovered numerous vulnerabilities in SSH services while investigating the xz backdoor.
- Many issues were found in devices like wireless access points, routers, and firewalls.
- Old SSH features and poor implementation practices are often to blame.
- Critical vulnerabilities include unauthenticated information exposure and brute force attack susceptibility.
- runZero released a tool called SSHamble to help test and identify SSH vulnerabilities.