SSH Vulnerable to Terrapin Attack - Spiceworks (2024)

The Terrapin vulnerability CVE-2023-48795 compromises secure access to network services, posing a threat to internet security.

SSH Vulnerable to Terrapin Attack - Spiceworks (2)
  • Security researchers have discovered a new vulnerability called Terrapin that impacts the Secure Shell (SSH) network protocol.
  • According to the study, at least 77% of SSH servers support modes that can be exploited through the vulnerability.

Security researchers from Germany’s Ruhr University Bochum have found a vulnerability in Secure Shell (SSH) cryptographic network protocol that can enable malicious actors to reduce protections in what is normally considered a secure channel. The vulnerability is known as Terrapin, the CVE-2023-48795, which is a prefix truncation attack.

The Terrapin vulnerability allows attackers to extract messages from servers and clients by making changes to sequence numbers during handshake processes to establish secure communication channels. This reduces the security of the connections, weakening authentication algorithms and stopping protections against attacks that involve timing keystrokes.

See More: 1.3M LoanCare Borrowers Data Exfiltrated in Fidelity National Financial Breach

The vulnerability is the very first practically exploitable prefix truncation attack found by researchers, which is part of a new group of attacks that primarily target cryptographic network protocols.

To execute a Terrapin attack, threat actors need the capabilities to perform man-in-the-middle attacks to adjust traffic at the network layer. They especially affect encryption algorithms with the -cbc suffix.

Using vulnerability scanners has been recommended to check for susceptible servers and clients. In addition, client and server updates and long-term awareness programs will be required to stave off the effects of the Terrapin vulnerability.

What measures does your organization follow to mitigate security vulnerabilities? Let us know your thoughts on LinkedInOpens a new window , XOpens a new window , or FacebookOpens a new window . We’d love to hear from you!

Image source: Shutterstock

LATEST NEWS STORIES

SSH Vulnerable to Terrapin Attack - Spiceworks (3)

Anuj Mudaliar is a content development professional with a keen interest in emerging technologies, particularly advances in AI. As a tech editor for Spiceworks, Anuj covers many topics, including cloud, cybersecurity, emerging tech innovation, AI, and hardware. When not at work, he spends his time outdoors - trekking, camping, and stargazing. He is also interested in cooking and experiencing cuisine from around the world.

SSH Vulnerable to Terrapin Attack - Spiceworks (4)

Do you still have questions? Head over to the Spiceworks Community to find answers.

SSH Vulnerable to Terrapin Attack - Spiceworks (2024)
Top Articles
The world’s blackest paint: How it works
Log in - Human Capital Institute
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
The Idol - watch tv show streaming online
Calamity Hallowed Ore
Visustella Battle Core
Dark Souls 2 Soft Cap
Southland Goldendoodles
How Many Slices Are In A Large Pizza? | Number Of Pizzas To Order For Your Next Party
2024 U-Haul ® Truck Rental Review
Chastity Brainwash
60 X 60 Christmas Tablecloths
Noaa Ilx
Account Suspended
Hdmovie 2
Joan M. Wallace - Baker Swan Funeral Home
Bethel Eportal
MyCase Pricing | Start Your 10-Day Free Trial Today
Caring Hearts For Canines Aberdeen Nc
Reicks View Farms Grain Bids
Foodsmart Jonesboro Ar Weekly Ad
Unable to receive sms verification codes
Sandals Travel Agent Login
3 Ways to Format a Computer - wikiHow
Osrs Important Letter
3473372961
Ridge Culver Wegmans Pharmacy
Boondock Eddie's Menu
Sitting Human Silhouette Demonologist
Rocketpult Infinite Fuel
Does Iherb Accept Ebt
Merge Dragons Totem Grid
Case Funeral Home Obituaries
Sams La Habra Gas Price
Streameast.xy2
Claim loopt uit op pr-drama voor Hohenzollern
Joey Gentile Lpsg
Sabrina Scharf Net Worth
World Social Protection Report 2024-26: Universal social protection for climate action and a just transition
Ross Dress For Less Hiring Near Me
Jetblue 1919
Leland Nc Craigslist
Thotsbook Com
Craigslist Com St Cloud Mn
Underground Weather Tropical
Maurices Thanks Crossword Clue
Sj Craigs
Edict Of Force Poe
What Is The Gcf Of 44J5K4 And 121J2K6
Psalm 46 New International Version
Asisn Massage Near Me
E. 81 St. Deli Menu
Latest Posts
Article information

Author: Margart Wisoky

Last Updated:

Views: 6049

Rating: 4.8 / 5 (58 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Margart Wisoky

Birthday: 1993-05-13

Address: 2113 Abernathy Knoll, New Tamerafurt, CT 66893-2169

Phone: +25815234346805

Job: Central Developer

Hobby: Machining, Pottery, Rafting, Cosplaying, Jogging, Taekwondo, Scouting

Introduction: My name is Margart Wisoky, I am a gorgeous, shiny, successful, beautiful, adventurous, excited, pleasant person who loves writing and wants to share my knowledge and understanding with you.