Differences
This shows you the differences between the selected revisions of the page.
2019-11-01 | 2020-01-13 | ||
sshbug_winadj anchor (martin) | removing no longer valid statement (martin) | ||
Line 88: | Line 88: | ||
If this bug is detected, WinSCP will stop using ignore messages. This means that keepalives will stop working, and WinSCP will have to fall back to a secondary defense against [[#sshbug_plainpw1|SSH-1 password-length eavesdropping]]. If this bug is enabled when talking to a correct server, the session will succeed, but keepalives will not work and the session might be more vulnerable to eavesdroppers than it could be. | If this bug is detected, WinSCP will stop using ignore messages. This means that keepalives will stop working, and WinSCP will have to fall back to a secondary defense against [[#sshbug_plainpw1|SSH-1 password-length eavesdropping]]. If this bug is enabled when talking to a correct server, the session will succeed, but keepalives will not work and the session might be more vulnerable to eavesdroppers than it could be. | ||
- | |||
- | This is an %%SSH-1%%-specific bug. No known %%SSH-2%% server fails to deal with %%SSH-2%% ignore messages. | ||
===== [[sshbug_plainpw1]] Refuses all SSH-1 password camouflage ===== | ===== [[sshbug_plainpw1]] Refuses all SSH-1 password camouflage ===== |