{"id":13443,"date":"2024-01-17T12:12:25","date_gmt":"2024-01-17T06:12:25","guid":{"rendered":"https:\/\/dtasiagroup.com\/?p=13443"},"modified":"2024-06-19T16:21:56","modified_gmt":"2024-06-19T10:21:56","slug":"the-terrapin-attack-vulnerability-in-the-ssh-protocol-how-to-stay-secure","status":"publish","type":"post","link":"https:\/\/dtasiagroup.com\/vi\/the-terrapin-attack-vulnerability-in-the-ssh-protocol-how-to-stay-secure\/","title":{"rendered":"The Terrapin Attack Vulnerability in the SSH Protocol &#8211; How to Stay Secure"},"content":{"rendered":"<div class=\"elementor-element elementor-element-b43a3a7 elementor-widget elementor-widget-image\" data-id=\"b43a3a7\" data-element_type=\"widget\" data-settings=\"{&quot;ekit_we_effect_on&quot;:&quot;none&quot;}\" data-widget_type=\"image.default\">\n<div id=\"fragment-826\" class=\"content-fragment blog-post-poster no-wrapper with-spacing responsive-1\" data-reflow=\"_p_content,_p_singlecolumn,1,1,7\">\n<div class=\"content-fragment-content\">\n<div class=\"content full text\">\n<div class=\"poster\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-13447 size-full\" src=\"https:\/\/dtasiagroup.com\/wp-content\/uploads\/2024\/01\/download-2-1.jpg\" alt=\"\" width=\"800\" height=\"400\" \/><\/div>\n<\/div>\n<\/div>\n<div class=\"content-fragment-footer\"><\/div>\n<\/div>\n<div id=\"fragment-827\" class=\"content-fragment blog-post no-wrapper with-spacing responsive-1\" data-reflow=\"_p_content,_p_singlecolumn,1,1,8\">\n<div class=\"content-fragment-content\">\n<div class=\"content full text\">\n<div class=\"content\">\n<p>&nbsp;<\/p>\n<p>The Secure Shell (SSH) protocol is widely utilized for secure remote access to servers, services, applications, and automated file transfers, with millions of connections established weekly.<\/p>\n<p>SSH Communication Security, the company that developed the SSH protocol, recently learned of a new vulnerability (CVE-2023-48795) named Terrapin, which poses a potential downgrade attack affecting SSH connections.<\/p>\n<p>Impact of Terrapin Attack: Fortunately, the vulnerability is categorized as moderate, as assessed by SSH Communication Security and corroborated by RedHat. However, it remains concerning due to its capability to downgrade the security of SSH connections, albeit the likelihood of exploitation is low. This vulnerability spans multiple products and encryption ciphers, which is relatively uncommon.<\/p>\n<p>Terrapin Attack Details: Terrapin leverages prefix truncation to potentially enable attackers to downgrade secure signature algorithms and disable certain security measures against keystroke timing attacks in OpenSSH. While this vulnerability could facilitate man-in-the-middle (MitM) attacks, it requires interception of the connection. Additionally, the session must be protected by either ChaCha20-Poly1305 or CBC with Encrypt-then-MAC encryption modes, which are widely used globally.<\/p>\n<p>For a detailed explanation of the Terrapin attack, visit the <a href=\"https:\/\/terrapin-attack.com\/\" target=\"_new\" rel=\"noreferrer noopener\">Terrapin Attack page<\/a>.<\/p>\n<p>Assessing Terrapin SSH Risk Posture: As SSH protocol experts, we provide tools to assist organizations in securing their networks, especially those heavily reliant on SSH. While the impact of the Terrapin vulnerability may not be severe for your organization, it underscores the importance of Secure Shell governance, an often overlooked aspect of security.<\/p>\n<p>Our SSH Risk Assessment Service identifies vulnerable servers susceptible to the Terrapin attack, allowing you to upgrade them at your convenience without the hassle of identification. We also:<\/p>\n<ul>\n<li>Identify SSH keys used for authentication, critical in large IT environments where their numbers can be substantial.<\/li>\n<li>Detect policy and compliance breaches such as weak cryptographic algorithms or inadequate key sizes.<\/li>\n<li>Prepare comprehensive reports for IT audits, outlining environment status and recommendations for compliance.<\/li>\n<li>Prevent security control bypasses like PAM bypasses commonly exploited via SSH keys.<\/li>\n<li>Provide guidance on enhancing SSH key governance through recommended next steps.<\/li>\n<\/ul>\n<p>For a quick start to improving SSH security posture, explore our SSHerlock Discovery &amp; Audit Self-service tool. Sign up <a href=\"\/vi\/link\/\" rel=\"noreferrer\">here<\/a> to begin.<\/p>\n<p>Consider our Universal SSH Key Manager, recognized as the most comprehensive software for managing SSH key lifecycles, facilitating migration to a keyless authentication model.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p>&nbsp;<\/p>\n<p>Source:\u00a0<a href=\"https:\/\/www.ssh.com\/blog\/the-terrapin-attack-vulnerability-in-the-ssh-protocol-how-to-stay-secure\">https:\/\/www.ssh.com\/blog\/the-terrapin-attack-vulnerability-in-the-ssh-protocol-how-to-stay-secure<\/a><\/p>\n<p>&nbsp;<\/p>\n<p><strong>Gi\u1edbi thi\u1ec7u v\u1ec1 DT Asia<\/strong><\/p>\n<p>DT Asia \u0111\u01b0\u1ee3c th\u00e0nh l\u1eadp v\u00e0o n\u0103m 2007 v\u1edbi s\u1ee9 m\u1ec7nh r\u00f5 r\u00e0ng l\u00e0 x\u00e2y d\u1ef1ng b\u01b0\u1edbc th\u00e2m nh\u1eadp th\u1ecb tr\u01b0\u1eddng cho c\u00e1c gi\u1ea3i ph\u00e1p b\u1ea3o m\u1eadt CNTT ti\u00ean phong kh\u00e1c nhau t\u1eeb M\u1ef9, Ch\u00e2u \u00c2u v\u00e0 Israel.<\/p>\n<p>Ng\u00e0y nay, DT Asia l\u00e0 nh\u00e0 ph\u00e2n ph\u1ed1i gi\u00e1 tr\u1ecb gia t\u0103ng khu v\u1ef1c v\u1ec1 c\u00e1c gi\u1ea3i ph\u00e1p an ninh m\u1ea1ng, cung c\u1ea5p c\u00e1c c\u00f4ng ngh\u1ec7 ti\u00ean ti\u1ebfn cho c\u00e1c c\u01a1 quan ch\u00ednh ph\u1ee7 tr\u1ecdng \u0111i\u1ec3m v\u00e0 c\u00e1c kh\u00e1ch h\u00e0ng h\u00e0ng \u0111\u1ea7u thu\u1ed9c khu v\u1ef1c t\u01b0 nh\u00e2n, bao g\u1ed3m c\u00e1c ng\u00e2n h\u00e0ng to\u00e0n c\u1ea7u v\u00e0 c\u00e1c c\u00f4ng ty thu\u1ed9c danh s\u00e1ch Fortune 500. Ch\u00fang t\u00f4i c\u00f3 c\u00e1c v\u0103n ph\u00f2ng v\u00e0 \u0111\u1ed1i t\u00e1c kh\u1eafp khu v\u1ef1c Ch\u00e2u \u00c1 - Th\u00e1i B\u00ecnh D\u01b0\u01a1ng nh\u1eb1m th\u1ea5u hi\u1ec3u r\u00f5 h\u01a1n c\u00e1c th\u1ecb tr\u01b0\u1eddng v\u00e0 cung c\u1ea5p c\u00e1c gi\u1ea3i ph\u00e1p mang t\u00ednh b\u1ea3n \u0111\u1ecba h\u00f3a.<\/p>","protected":false},"excerpt":{"rendered":"<p>The\u00a0Secure Shell (SSH)\u00a0is a widely-used protocol that provides (remote) secure access to servers, services, and applications &#8211; and between them for automated file transfers. These connections are measured in the millions per week.\u00a0&#x200d;<\/p>","protected":false},"author":11,"featured_media":13447,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-13443","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-articles"],"_links":{"self":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13443","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/comments?post=13443"}],"version-history":[{"count":0,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/posts\/13443\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media\/13447"}],"wp:attachment":[{"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/media?parent=13443"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/categories?post=13443"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dtasiagroup.com\/vi\/wp-json\/wp\/v2\/tags?post=13443"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}