Week 9
Welp, it looks like I missed Week 8. I’ll be posting for “Week 8″ later, even though it’s extremely late.
Anyways! Today’s topic is the recent vulnerability in LibSSH. On BleepingComputer, there is an article discussing the recently-discovered issue whereby users of LibSSH were easily compromised by an unexpected and fairly simplistic attack vector - sending a userauth success message to the target SSH server will cause an unpatched server to provide the attacker login access as though they had successfully authenticated, when in reality no authentication had even been performed.
Read the article below for more information:
https://www.bleepingcomputer.com/news/security/libssh-cve-2018-10933-scanners-and-exploits-released-apply-updates-now/

















