<?xml version="1.0" encoding="ISO-8859-1"?>
  <rss version="0.92">
    <channel>
      <title>SecuObs.com</title>
      <link>http://www.secuobs.com</link>
      <description>L'observatoire de la securite Internet</description>
      <language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 
 <item>
 <title>PuttyHijack session hijack POC   ...</title>
 <description>PuttyHijack session hijack POC
 http://www.secuobs.com/revue/news/332182.shtml</description>
 <link>http://www.secuobs.com/news/comments215112008-openssh_cbc_ctr_aes_cpni.shtml#11058</link>
 <guid>http://www.secuobs.com/news/comments215112008-openssh_cbc_ctr_aes_cpni.shtml#11058</guid>
 </item>
 
 <item>
 <title>ESRT @opexxx - Useless OpenSSH resources exhausion bug via GSSAPI   ...</title>
 <description>ESRT @opexxx - Useless OpenSSH resources exhausion bug via GSSAPI
 http://www.secuobs.com/twitter/news/233878.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#10351</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#10351</guid>
 </item>
 
 <item>
 <title>ESRT @adulau @jedisct1 - Erlang OTP SSH Library Random Number Generator Weakness   ...</title>
 <description>ESRT @adulau @jedisct1 - Erlang OTP SSH Library Random Number Generator Weakness
 http://www.secuobs.com/twitter/news/233656.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#10346</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#10346</guid>
 </item>
 
 <item>
 <title>ESRT @digininja @n00bznet @kingcope - As promised: OpenSSH 35p1 Remote Root Exploit for FreeBSD -- I would verify this   ...</title>
 <description>ESRT @digininja @n00bznet @kingcope - As promised: OpenSSH 35p1 Remote Root Exploit for FreeBSD -- I would verify this
 http://www.secuobs.com/twitter/news/223010.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#10001</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#10001</guid>
 </item>
 
 <item>
 <title>ESRT @adulau @damienmiller - Did Redhat just fix OpenSSH by making it seed with only 6 bytes from /dev/random?   ...</title>
 <description>ESRT @adulau @damienmiller - Did Redhat just fix OpenSSH by making it seed with only 6 bytes from /dev/random?
 http://www.secuobs.com/twitter/news/214247.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#9835</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#9835</guid>
 </item>
 
 <item>
 <title>ESRT @packet_storm - OpenSSH 5.8p2    ...</title>
 <description>ESRT @packet_storm - OpenSSH 5.8p2 
 http://www.secuobs.com/twitter/news/202225.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#9542</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#9542</guid>
 </item>
 
 <item>
 <title>ESRT @VUPEN - OpenSSH v5.8 was released to fix an information disclosure vulnerability   ...</title>
 <description>ESRT @VUPEN - OpenSSH v5.8 was released to fix an information disclosure vulnerability
 http://www.secuobs.com/twitter/news/170440.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#8827</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#8827</guid>
 </item>
 
 <item>
 <title>FreeSSHD 1.2.4 Remote Buffer Overflow DoS   ...</title>
 <description>FreeSSHD 1.2.4 Remote Buffer Overflow DoS
 http://www.secuobs.com/revue/news/204207.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#5478</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#5478</guid>
 </item>
 
 <item>
 <title>ProSSHD v1.2 20090726 Buffer Overflow Exploit   ...</title>
 <description>ProSSHD v1.2 20090726 Buffer Overflow Exploit
 http://www.secuobs.com/revue/news/197312.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#5260</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#5260</guid>
 </item>
 
 <item>
 <title>openssh-53p1-remote-root.c   ...</title>
 <description>openssh-53p1-remote-root.c
 http://www.secuobs.com/revue/news/189359.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#4919</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#4919</guid>
 </item>
 
 <item>
 <title>Hacking the OpenSSH library for Ncrack    ...</title>
 <description>Hacking the OpenSSH library for Ncrack 
 http://www.secuobs.com/revue/news/126423.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#2524</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#2524</guid>
 </item>
 
 <item>
 <title>ESRT @thierryzoller - Fake OpenSSH 0pen0wn shellcode dissasembled   ...</title>
 <description>ESRT @thierryzoller - Fake OpenSSH 0pen0wn shellcode dissasembled
 http://www.secuobs.com/twitter/news/8796.shtml</description>
 <link>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#2352</link>
 <guid>http://www.secuobs.com/news/comments115112008-openssh_cbc_ctr_aes_cpni.shtml#2352</guid>
 </item>
 
 <item>
 <title>ESRT @danielcid - reply from ssh on the 0-day rumors     ...</title>
 <description>ESRT @danielcid - reply from ssh on the 0-day rumors
 http://www.secuobs.com/twitter/news/7572.shtml
 </description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2286</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2286</guid>
 </item>
 
 <item>
 <title>ESRT @hackerfantastic - SSH attack pcap capture made available     ...</title>
 <description>ESRT @hackerfantastic - SSH attack pcap capture made available
 http://www.secuobs.com/twitter/news/7528.shtml
 </description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2284</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2284</guid>
 </item>
 
 <item>
 <title>Unverified : ESRT @cykyc 0day openssh 43 remote exploit via @mubix @Gh0u1 ...</title>
 <description>Unverified : ESRT @cykyc 0day openssh 43 remote exploit via @mubix @Gh0u1</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2262</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2262</guid>
 </item>
 
 <item>
 <title>ESRT @mubix A very effective SSH bruteforcer by @laramies recently updated   ...</title>
 <description>ESRT @mubix A very effective SSH bruteforcer by @laramies recently updated
 http://www.secuobs.com/twitter/news/6657.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2218</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#2218</guid>
 </item>
 
 <item>
 <title>Using and Extending Kojoney SSH Honeypot   ...</title>
 <description>Using and Extending Kojoney SSH Honeypot
 http://www.secuobs.com/revue/news/100751.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#1585</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#1585</guid>
 </item>
 
 <item>
 <title>PUTTKyeak = PUTTY + KEYLOG + TWEAK   ...</title>
 <description>PUTTKyeak = PUTTY + KEYLOG + TWEAK
 http://www.secuobs.com/revue/news/100468.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#1579</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#1579</guid>
 </item>
 
 <item>
 <title>OpenSSH chink bares encrypted data packets   ...</title>
 <description>OpenSSH chink bares encrypted data packets
 http://www.secuobs.com/revue/news/98239.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#1521</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#1521</guid>
 </item>
 
 <item>
 <title>Sun Solaris SSH CBC Mode Plaintext Recovery Vulnérabilité   ...</title>
 <description>Sun Solaris SSH CBC Mode Plaintext Recovery Vulnérabilité
 http://www.secuobs.com/revue/news/43223.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#364</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#364</guid>
 </item>
 
 <item>
 <title>There was an error in the original advisory. The estimate of 32768 attempts to carry out a successful attack is incorrect. The correct estimate is 11356 attempts. A revised version is now available at ...</title>
 <description>There was an error in the original advisory. The estimate of 32768 attempts to carry out a successful attack is incorrect. The correct estimate is 11356 attempts. A revised version is now available at:
 http://www.openssh.com/txt/cbc.adv
 The advisory and its recommendations are otherwise unchanged.
 
 Vu sur bugtraq >>> http://secuobs.com/secumail/btsecumail/
 </description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#324</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#324</guid>
 </item>
 
 <item>
 <title>la réponse d'openssh    ...</title>
 <description>la réponse d'openssh 
 http://www.secuobs.com/secumail/btsecumail/msg14449.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#321</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#321</guid>
 </item>
 
 <item>
 <title>alerte secunia relative aujourd'hui   ...</title>
 <description>alerte secunia relative aujourd'hui
 http://secuobs.com/secumail/snsecumail/msg13006.shtml</description>
 <link>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#313</link>
 <guid>http://www.secuobs.com/news/comments15112008-openssh_cbc_ctr_aes_cpni.shtml#313</guid>
 </item>
 
    </channel>
  </rss>
