是openssh 22端口的漏洞,描述是diffie-hellman key agreement protocol存在资源管理错误漏洞,远程攻击者可以发送实际上不是公钥的任意数字,并出发服务端dhe模幂计算。
(0)
最佳答案
规避方法:Key exchange algorithms不使用dh相关算法
[2015]ssh2 algorithm key-exchange ?
dh-group-exchange-sha1 Diffie-Hellman-group-exchange-SHA1
dh-group1-sha1 Diffie-Hellman-group1-SHA1
dh-group14-sha1 Diffie-Hellman-group14-SHA1
ecdh-sha2-nistp256 Elliptic Curve Diffie-Hellman-SHA2-256
ecdh-sha2-nistp384 Elliptic Curve Diffie-Hellman-SHA2-384
比如
[2.14]ssh2 algorithm key-exchange ecdh-sha2-nistp256
(0)
参考此修复案例:https://zhiliao.h3c.com/Theme/details/206865
规避方法:
Key exchange algorithms不使用dh相关算法 [2015]ssh2 algorithm key-exchange ?
dh-group-exchange-sha1 Diffie-Hellman-group-exchange-SHA1
dh-group1-sha1 Diffie-Hellman-group1-SHA1
dh-group14-sha1 Diffie-Hellman-group14-SHA1
ecdh-sha2-nistp256 Elliptic Curve Diffie-Hellman-SHA2-256
ecdh-sha2-nistp384 Elliptic Curve Diffie-Hellman-SHA2-384
比如
[2.14]ssh2 algorithm key-exchange ecdh-sha2-nistp256
(0)
cve-2002-20001
cve-2002-20001
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明