{"id":31996,"date":"2017-06-05T06:45:05","date_gmt":"2017-06-05T10:45:05","guid":{"rendered":"http:\/\/www.opensource.im\/uncategorized\/ssh-configuration-on-nexpose-servers-allowed-weak-encryption-algorithms-threatpost.php"},"modified":"2017-06-05T06:45:05","modified_gmt":"2017-06-05T10:45:05","slug":"ssh-configuration-on-nexpose-servers-allowed-weak-encryption-algorithms-threatpost","status":"publish","type":"post","link":"https:\/\/euvolution.com\/open-source-convergence\/encryption\/ssh-configuration-on-nexpose-servers-allowed-weak-encryption-algorithms-threatpost.php","title":{"rendered":"SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms &#8211; Threatpost"},"content":{"rendered":"<p><p>    Rapid7 encouraged owners of its Nexpose appliancesthis    week to apply an update to their systems to tweak how SSH is    configured by default.  <\/p>\n<p>    The company warned on Wednesday the devices were shipped with    an SSH configuration that could have let some obsolete KEX,    encryption and MAC algorithms be used for key exchange.  <\/p>\n<p>    Nexpose devices are preconfigured servers, deployed in server    racks, designed to help users gauge vulnerabilities, manage    vulnerability data, and limit threat exposure. All physical    Nexpose appliances are affected per     a disclosure by Samuel Huckins, a program manager with the    company, published on Wednesday.  <\/p>\n<p>      Disclosure on CVE-2017-5243: Nexpose hardware appliance SSH      enabled obsolete algorithms <a href=\"https:\/\/t.co\/DHI7uLJ5yj\" rel=\"nofollow\">https:\/\/t.co\/DHI7uLJ5yj<\/a> (Thanks      to @LiamMSomerville)    <\/p>\n<p>       Rapid7 (@rapid7) May      31, 2017    <\/p>\n<p>    Liam Somerville, a researcher based in Scotland, discovered the    vulnerability (CVE-2017-5243) and reported it to the company    three weeks ago.  <\/p>\n<p>    Nothing needs to be downloaded to resolve the issue, but a file    does need to edited, Rapid7 said. According to Huckins, to fix    the vulnerability a user with root access has to edit    \/etc\/ssh\/sshd_config in the appliance to ensure only modern    ciphers, key exchange, and MAC algorithms are accepted. This    should lessen the likelihoodof any attacks involving    authentication.  <\/p>\n<p>    Prior to the fix, weak and out of date encryption algorithms    such asAES192-CBC, Blowfish-CBC, and 3DES-CBC, and KEX    algorithms such asdiffie-hellman-group-exchange-sha1,    could have been enabled.  <\/p>\n<p>    This change should not impact connections from Nexpose    instances to the physical appliance. The main impact is shoring    up access by SSH clients such that they cannot connect to the    appliance using obsolete algorithms, Huckins wrote.  <\/p>\n<p>    According to Tod Beardsley, Research Director at Rapid7, the    vulnerability could have let an attacker in a privileges    position on the network force an algorithm downgrade between an    SSH client and Nexpose during authentication.  <\/p>\n<p>    The privileged position is crucial to making the attack a    success, since its a man-in-the-middle (MitM) attack  first,    the attacker needs to be able to insert himself between the    client and server, which usually means the attacker is on the    same network as either endpoint, or has compromised an ISP    along the way (in which case you have bigger problems),    Beardsley told Threatpost late Friday, Once there, the    attacker can pose as both sides of the initial SSH handshake,    and rewrite the handshake to request one of these older,    obsolete algorithms. Once thats done, the attacker then    records the session, and then can decrypt the session offline.  <\/p>\n<p>    Beardsley says that removing server-side support for the    algorithms makes the aforementioned kind of attack impractical    and that overall, the actual risk of exploitation is fairly    low.  <\/p>\n<p>    These appliances dont tend to be exposed on public networks,    so attackers need to be on the inside to begin with,    Beardsley said,  The whole point of SSH is to be resistant to    this kind of session meddling, even in the face of an attacker    whos in the right place and has the right expertise and    resources to mount this sort attack. By strengthening whats    available on the server, we can help keep that promise of    confidentiality.  <\/p>\n<p>    *This article was updated at 4:30 p.m. EST to include    comments from Tod Beardsley of Rapid7.  <\/p>\n<p><!-- Auto Generated --><\/p>\n<p>See the original post:<br \/>\n<a target=\"_blank\" href=\"https:\/\/threatpost.com\/ssh-configuration-on-nexpose-servers-allowed-weak-encryption-algorithms\/126046\/\" title=\"SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms - Threatpost\">SSH Configuration on Nexpose Servers Allowed Weak Encryption Algorithms - Threatpost<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p> Rapid7 encouraged owners of its Nexpose appliancesthis week to apply an update to their systems to tweak how SSH is configured by default. <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[],"class_list":["post-31996","post","type-post","status-publish","format-standard","hentry","category-encryption"],"_links":{"self":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/31996"}],"collection":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/comments?post=31996"}],"version-history":[{"count":0,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/posts\/31996\/revisions"}],"wp:attachment":[{"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/media?parent=31996"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/categories?post=31996"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/euvolution.com\/open-source-convergence\/wp-json\/wp\/v2\/tags?post=31996"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}