[30003] in bugtraq
Re: OpenSSH/PAM timing attack allows remote users identification
daemon@ATHENA.MIT.EDU (ilja van sprundel)
Fri May 2 14:17:13 2003
Date: 1 May 2003 23:59:13 -0000
Message-ID: <20030501235913.18782.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: ilja van sprundel <ilja@netric.org>
To: bugtraq@securityfocus.com
In-Reply-To: <Pine.LNX.4.30L2.0304301358220.9889-200000@dns.mediaservice.net>
hm, this has been known for some time,
and stealth of teso wrote a nice paper and some
example tools for stuff like that :
http://www.team-teso.net/releases/epta.tgz