• @mumblerfish
    link
    376 months ago

    If I’m not mistaken, it seems like this is a timing attack and you need a lot of attack attempts to make it work. If you have like a fail2ban rule for ssh it should mitigate this attack to quite some degree, right? (Of course updating would still be the best).

    • shastaxc
      link
      fedilink
      126 months ago

      While statistically unlikely, it would be possible to exploit the vulnerability on the first attempt