<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-13462206.post3992226397490897300..comments</id><updated>2011-07-06T23:29:36.562+02:00</updated><category term='Livo'/><category term='Biométrie'/><category term='XML SAML OpenID Windows CardSpace User'/><category term='Strong Authentication'/><category term='Clavid Yubico OpenID'/><category term='Usurpation d&apos;identité'/><category term='Ethical Technologies Identity Geneva Unesco'/><category term='PEM'/><category term='Biométrie Iris'/><category term='Reprise'/><category term='XML SOAP SAML WS-Signature WS-Encryption'/><category term='OpenID Authentification Forte'/><category term='Risk Based Authentication'/><category term='PingIdentity'/><category term='OCRA'/><category term='Insecure Keylogger'/><category term='Private Key X509 PKI IE exploit'/><category term='Vol identités numériques'/><category term='ANSI'/><category term='Identity'/><category term='Coffre forte électronique'/><category term='Attacks MiM DH OpenID Authentification Forte'/><category term='base64'/><category term='PCI-DSS'/><category term='RSA PKI X509'/><category term='PKI Biométrie Match on Card OCSP'/><category term='Identity Theft'/><category term='EMV-CAP'/><category term='Identités numérique'/><category term='eToken Authentification Forte'/><category term='Mots de passe'/><category term='Fingerprint reader MS bypass Microsoft'/><category term='OpenID David Recordon'/><category term='Authentification forte'/><category term='Sxip'/><category term='Crack Password Authentification forte Wireless Keyboard'/><category term='Munities Biométrie'/><category term='SAML PKI idp Digital ID Identity'/><category term='Sniffer'/><category term='http://www.portknocking.org/'/><category term='Web 2.0 Identités numériques Empreinte numérique'/><category term='SMS'/><category term='Infocard Cardspace'/><category term='MOC'/><category term='SSH'/><category term='DNA'/><category term='Check Point User Conference'/><category term='trustbearer.com'/><category term='Personal Portable Security Device'/><category term='FFR'/><category term='TPM'/><category term='brute force'/><category term='SMS OTP Certificat'/><category term='Out of Band Authentication'/><category term='OATH OTP SmartCard ICT'/><category term='CAPTCHA'/><category term='openssl'/><category term='IDSP'/><category term='XML'/><category term='Authentification Forte H1N1 Grippe A VPN SSL VPN IPSEC'/><category term='ID Selector OpenID'/><category term='smartphone'/><category term='FAR'/><category term='Xiring'/><category term='Mobile OTP'/><category term='OpenID'/><category term='Man-in-the-Browser'/><category term='CSR'/><category term='OpenID  Biometry'/><category term='MitB'/><category term='Digital ID OpenID Microsoft Open Specification Promise'/><category term='NTX'/><category term='OAUTH OpenID'/><category term='Identités numériques'/><category term='identityblog'/><category term='Webilus'/><category term='Authentication forte'/><category term='New Intrusion Tolerance Technology Treats Attacks as Inevitable'/><category term='OpenID Certificat Authentification Forte'/><category term='CRL'/><category term='Yubico'/><category term='Theft Prevention'/><category term='DDOS'/><category term='Pumpkin Hash'/><category term='OpenSSH'/><category term='SSTIC'/><category term='LASEC'/><category term='Cryptographic Filesystems'/><category term='Match on Card'/><category term='HSPD-12 PKI SAML'/><category term='The Tao of Authentication'/><category term='SSTIC 2009'/><category term='Iphone'/><category term='SecurID'/><category term='MITM'/><category term='Facebook OpenID'/><category term='OATH'/><category term='ISO'/><category term='Banana Security Biométrie Biometry'/><category term='Banker'/><category term='ANSI 378'/><category term='ADN'/><category term='Phone Factor'/><category term='Token USB'/><category term='Identité numérique'/><category term='Extended Validation'/><category term='Keyboard'/><category term='identité 2.0'/><category term='Avatar'/><category term='2FA'/><category term='L&apos;identité numériquelien technologique  entité réelle entité virtuelle'/><category term='Kim Cameron'/><category term='e-Xpert Solutions'/><category term='EMV'/><category term='Verayo'/><category term='SAML SSO'/><category term='OTP'/><category term='Biométrie Mobilité Authentification Forte'/><category term='ANSI-BBB Identity'/><category term='EPFL'/><category term='Bankers'/><category term='EV Certificate'/><category term='UPEK'/><category term='Définition'/><category term='Cold Boot Attacks'/><category term='Keepass'/><category term='TEXT'/><category term='Certificat'/><category term='Veine Biométrie'/><category term='HOTP'/><category term='3D-secure'/><category term='Crypto'/><category term='The Information Card Foundation'/><category term='PIP X509 OTP OpenID'/><category term='MD6'/><category term='Biométrie USA'/><category term='Keylogger'/><category term='PCI'/><category term='Identitité numérique'/><category term='Confiance'/><category term='RCA'/><category term='PAPE OpenID'/><category term='OpenID Facebook Google'/><category term='Active Directory Root PKI'/><category term='DLP'/><category term='OpenID Clavid SSL Client Certificate'/><category term='Biométrie Match on Card Veine Sony'/><category term='Citadelle Electronique Sylvain Maret'/><category term='FAST'/><category term='Match on Card Biométrie Authentification Forte PKI'/><category term='WS SOAP XML Axis'/><category term='ASF-WS'/><category term='wikipedia'/><category term='X509'/><category term='TOTP'/><category term='Strong Authentication; RSA; PKI; X509; SecurID; OTP; HOTP; TOTP; OpenID; OWASP; OATH; FFIEC'/><category term='EMV CAP Authentification Forte'/><category term='HSPD-12'/><category term='PKI'/><category term='eBanking Sécurité Authentification Forte'/><category term='SecurID; Hack; RSA; OTP; Seed; OATH'/><category term='Citizen ID Forum'/><category term='FIPS-201'/><category term='Checkpoint'/><category term='Vascular Pattern Recognition'/><category term='SAML OpenID PAPE'/><category term='saml'/><category term='Smartcard'/><category term='Botnet'/><category term='RFID'/><category term='Biométrie AD Microsoft'/><category term='SMS OATH Mobile'/><category term='Reconstructing Fingerprints from Minutiae Points'/><category term='Cardspace vs OpenID'/><category term='Yubikey'/><category term='OWASP OpenID'/><category term='DOS'/><title type='text'>Comments on La Citadelle Electronique:  Identité Numérique et Authentification Forte: OpenSSH: Furtivité et Hardening avec une authentif...</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.citadelle-electronique.net/feeds/3992226397490897300/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html'/><author><name>Sylvain Maret</name><uri>http://www.blogger.com/profile/04336297227186666432</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='21' height='32' src='http://3.bp.blogspot.com/_QntNf2b8LN8/SvG_8y8U6DI/AAAAAAAAHcg/k31ODCy9euU/S220/sylvain+cool+3.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-13462206.post-5769856180392077946</id><published>2011-07-06T23:29:36.562+02:00</published><updated>2011-07-06T23:29:36.562+02:00</updated><title type='text'>Thanks Dug, I will have a look

Sylvain</title><content type='html'>Thanks Dug, I will have a look&lt;br /&gt;&lt;br /&gt;Sylvain</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5769856180392077946'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5769856180392077946'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309987776562#c5769856180392077946' title=''/><author><name>smaret</name><uri>http://smaret.clavid.ch/</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='15908526881261538232'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-799738138'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-3395124157076164540</id><published>2011-07-06T16:25:21.606+02:00</published><updated>2011-07-06T16:25:21.606+02:00</updated><title type='text'>This is an old exploit in OPIE, the one-time passw...</title><content type='html'>This is an old exploit in OPIE, the one-time password library on FreeBSD, not OpenSSH. See http://seclists.org/fulldisclosure/2011/Jul/0 and http://site.pi3.com.pl/adv/libopie-adv.txt&lt;br /&gt;&lt;br /&gt;For a better two-factor implementation for OpenSSH (that works with pubkey auth as well - PAM does not), check out http://www.duosecurity.com&lt;br /&gt;&lt;br /&gt;Full disclosure: I&amp;#39;m a co-founder of Duo Security - and an OpenSSH author. :-)</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/3395124157076164540'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/3395124157076164540'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309962321606#c3395124157076164540' title=''/><author><name>Dug</name><uri>http://www.blogger.com/profile/02438933976359733399</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-822540053'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-5261832063548407484</id><published>2011-06-30T18:25:54.827+02:00</published><updated>2011-06-30T18:25:54.827+02:00</updated><title type='text'>Pour confirmer cela:

OpenSSH 3.5p1 Remote Root Ex...</title><content type='html'>Pour confirmer cela:&lt;br /&gt;&lt;br /&gt;OpenSSH 3.5p1 Remote Root Exploit For FreeBSD http://packetstormsecurity.org/files/102683 #exploit</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5261832063548407484'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/5261832063548407484'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309451154827#c5261832063548407484' title=''/><author><name>smaret</name><uri>http://smaret.clavid.ch/</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='15908526881261538232'/><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/openid16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-799738138'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-7799287640297454182</id><published>2011-06-30T16:56:57.446+02:00</published><updated>2011-06-30T16:56:57.446+02:00</updated><title type='text'>Le protocole SSH est, à ma connaissance,  dit « sû...</title><content type='html'>Le protocole SSH est, à ma connaissance,  dit « sûr » algorithmiquement. Ses vulnérabilités proviennent entres autres de défauts d’implantations, de l’acceptation de choses obsolètes pour raison de compatibilité (tel que le protocole 1, de vieux algorithmes, …). Le hardening et l’utilisation de la version la plus récente permettent de restreindre au mieux la surface d’attaque. Toutefois, l’erreur (ou l’oubli) étant humaine ou encore l’apparition de vulnérabilités méconnues n’étant pas à exclure, la furtivité permet de cacher toute information susceptible de mettre un attaquant sur la voie d’une vulnérabilité potentielle du protocole mis en place.&lt;br /&gt;Les attaques contre le protocole SSH sont multiples et il est difficile de dresser une liste représentative. Pour fixer les idées quant à ces attaques possibles contre openssh, par exemple, le site suivant fait un résumé de l’historique des vulnérabilités liées aux versions obsolètes : &lt;a href="http://www.openssh.org/fr/security.html" rel="nofollow"&gt;http://www.openssh.org/fr/security.html&lt;/a&gt;. Le chiffrement du handshake vise à éviter qu’un attaquant puisse facilement identifier une version obsolète du protocole utilisé, un chiffrement faible ou autre information qui permettrait d’utiliser une application automatisant l’attaque.&lt;br /&gt;&lt;br /&gt;En espérant que cela réponde à vos interrogations.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/7799287640297454182'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/7799287640297454182'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1309445817446#c7799287640297454182' title=''/><author><name>Anne Gosselin</name><uri>http://www.blogger.com/profile/18147474327369338111</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1235998680'/></entry><entry><id>tag:blogger.com,1999:blog-13462206.post-4461300654654340884</id><published>2011-06-17T09:31:24.932+02:00</published><updated>2011-06-17T09:31:24.932+02:00</updated><title type='text'>Merci pour ce billet très intéressant, j&amp;#39;ai ce...</title><content type='html'>Merci pour ce billet très intéressant, j&amp;#39;ai cependant une question sur la détermination de la version du SSH et sur l&amp;#39;écoute du Handshake.&lt;br /&gt;&lt;br /&gt;A ma connaissance, seule la version 1 du SSH est vulnérable et à moins d&amp;#39;utiliser des clés de chiffrement très faibles (asymétrique pour l&amp;#39;échange de clé et symétrique pour le chiffrement des flux), il est quasi-impossible d’arriver au bout de ce protocole.&lt;br /&gt;&lt;br /&gt;Il est sûr que l&amp;#39;OTP apporte une couche de sécurité supplémentaire, mais je souhaiterais savoir qu&amp;#39;elles sont les attaques réelles possibles contre ce protocole.&lt;br /&gt;&lt;br /&gt;Merci !</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/4461300654654340884'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/13462206/3992226397490897300/comments/default/4461300654654340884'/><link rel='alternate' type='text/html' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html?showComment=1308295884932#c4461300654654340884' title=''/><author><name>chevalier3as</name><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img1.blogblog.com/img/blank.gif'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://www.citadelle-electronique.net/2011/06/furtivite-et-hardening-avec-un.html' ref='tag:blogger.com,1999:blog-13462206.post-3992226397490897300' source='http://www.blogger.com/feeds/13462206/posts/default/3992226397490897300' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-626635301'/></entry></feed>
