vendor:
OpenSSH
by:
Nicolas Couture
N/A
CVSS
N/A
User Identification
CWE
Product Name: OpenSSH
Affected Version From: <= 3.6.p1
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2003
OpenSSH <= 3.6.p1 - User Identification
This script can be used to check whether a user exists on a remote server running OpenSSH. It relies on the timing difference between valid and invalid user login attempts to determine if a user exists or not. It is accurate against Red Hat boxes and Linux boxes running grsecurity, but not vulnerable on *BSD boxes which always have a 10-second delay.