logoalt Hacker News

jerrythegerbilyesterday at 5:12 AM3 repliesview on HN

An ssh server would exploit a vulnerability in the ssh client when it connects.

For example, openssh has both a client and server. There’s been vulnerabilities in openssh, in the client. Those vulnerabilities aren’t reachable unless you’re connecting to a server attempting to exploit you, so the risk is quite low because you know and trust most servers you’re connecting to with ssh.

To sum it up: Connecting to this server is probably fine, but in doing so most people are doing something significantly riskier without realizing it.


Replies

applfanboysbgonyesterday at 6:10 AM

There has never been a real-world OpenSSH exploit that allows a server to RCE a client that connected to it without a bunch of dubious qualifiers. Connecting to a random SSH server is much, much less dangerous than running a random binary or executing a random curl install script, both of which people do all the time, and is probably about on par with the likelihood of a random website escaping your browser's sandbox and RCEing you.

show 5 replies
teifereryesterday at 6:05 AM

> To sum it up: Connecting to this server is probably fine

And what are you basing this statement on?

show 1 reply
pydryyesterday at 11:35 AM

theoretically a browser could have the same vulnerability and has a vastly higher attack surface.

has there ever been an example of such a vulnerability in openssh?