Il semblerait que ce soit effectivement ça : non un code malveillant inséré dans le projet upstream de OpenSSH, mais une version modifiée et patchée qui, si elle est installée, ouvre l'accès par cette porte...
_They are not talking about the official OpenSSH code.
To save everyone a bit of time (and hassle with a PDF), from the same document:
"It allows a public key to be embedded in the sshd binary and will then always grant a root login shell if presented with the proper key pair for that key. [...] authorized_keys as a quick-and-easy method of persistence [...] obviously isn't very stealthy [...] The goal for this project was to provide the same level of persistence but embedded in the sshd binary itself (obviously, assuming root access, as before)"
In other works, no backdoor in sshd unless the system has already been rooted by other means and sshd replaced with a bugged binary. Boohoo._
Au temps pour moi. L'info sur cette possibilité n'en est pas moins inintéressante sur le principe.
Est-il possible de modifier le titre d'un journal après publication pour le rendre plus proche de la vérité (par un modérateur peut-etre) : Comment introduire une backdoor dans OpenSSH
[^] # Re: RAS
Posté par Xavier G. . En réponse au journal Une backdoor de la NSA dans OpenSSH ?. Évalué à 5.
Il semblerait que ce soit effectivement ça : non un code malveillant inséré dans le projet upstream de OpenSSH, mais une version modifiée et patchée qui, si elle est installée, ouvre l'accès par cette porte...
https://news.ycombinator.com/item?id=8905581
http://www.mail-archive.com/misc@openbsd.org/msg135510.html
_They are not talking about the official OpenSSH code.
To save everyone a bit of time (and hassle with a PDF), from the same document:
"It allows a public key to be embedded in the sshd binary and will then always grant a root login shell if presented with the proper key pair for that key. [...] authorized_keys as a quick-and-easy method of persistence [...] obviously isn't very stealthy [...] The goal for this project was to provide the same level of persistence but embedded in the sshd binary itself (obviously, assuming root access, as before)"
In other works, no backdoor in sshd unless the system has already been rooted by other means and sshd replaced with a bugged binary. Boohoo._
Au temps pour moi. L'info sur cette possibilité n'en est pas moins inintéressante sur le principe.
Est-il possible de modifier le titre d'un journal après publication pour le rendre plus proche de la vérité (par un modérateur peut-etre) : Comment introduire une backdoor dans OpenSSH