home.social

#terrapin — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #terrapin, aggregated by home.social.

fetched live
  1. There appears to be a terrapin in the river Avon, just next to the weir in central Bath. Looks like it's having a nice time.

    #terrapin #tortoise

  2. "BOW BEFORE ME, THE MASTER OF THE #POND!!
    … uh, could you give me a nudge? Seem to have beached myself."

    #Terrapin seen in Eltham Park whilst wandering the #LondonLoop

    #NaturePhotography #LoveLondonWalkLondon #London #photography

  3. The weather was so nice we walked to town through the woods. About 4 miles round trip. Met this guy along the way.



  4. ✅ Upcoming Fall USENIX Security

    Terrapin Attack: Breaking SSH Channel

    Tldr:

    🤘SSH ➡️ TCP ➡️ Unauthenticated (MiTM-able) Control Messages Hell.

    👉Put your SSH Session into an Stateless UDP Tunnel (eg. WireGuard) or use mosh.

    (Unauthenticated) TCP is a security mess from the 1980s and leads to false integrity assumptions (see China Great FireWall RST/ACKs) and has to finally die. Now.

    🤘Cryptographic agility will - sooner or later - ALWAYS translate direct into (downgrade) attack hell. Later is now.

    Generate SSH Ed25519 keys.
    👉 ssh-keygen -t ed25519

    Lock (Client & Server) your OpenSSH Cipher & Kex config.

    👉 Cipher: ChaCha20-Poly1305
    👉 KeyExchage: curve25519-sha256

    usenix.org/system/files/sec24f

    #ssh #openssh #security #downgrade #cipher #kex #terrapin #usenix

  5. Anyone for #tennis?
    Dear Friends as we may know.
    #Wombledon... eh #Wimbledon, will soon be upon us. Like #Peace. This morning our local tennis #courts in #Furzedown area, were being set up. On Tooting common all the courts were in full swing. Private tennis clubs? Probably #Streatham is the nearest one I am aware of. Anyway after a German breakfast (four pork sausages and sauerkraut) went for a 'morning constitutional' aka promenade...

    A
    #dinner #plate sized red-eared #terrapin was on the #path, making a break to a #nearby wet area. The conservation people try and restrict this refugee from #amazonian climes. Personally I believe we can be improved, by bringing in the #legendary #sewer #alligators of #NYC to eat some of our #water #quality executives. Which I feel is an apex predator courtesy. 😆

    I only brought my black hat and key, so no terrapin photos.

    This
    #afternoon the weather forecast is #Thunder #Thor and #Lightening and very sunny. Should be fun for #rainbow #seekers.

    Enjoying the
    #snails, which I have been watching in the garden, rather than relocating. The invasive Spanish slugs will be out in force soon.

    #Nature, can not fight it. Must #accept and work with. Anyways... time for me to try and get 'Mumble' working... or something similar for #coms on #Linux.

    Have a great day everyone
    ❤️

    #brekky #newyork #conservation #lake #pond

  6. It wasn't just the humans being bothered by flying insects today. The turtles in the lagoon had a damselfly that kept landing on their noses.

    #turtle #terrapin #reptile

  7. Атака на SSH и взлом туннелей VPN

    SSH стал практически стандартом де-факто для подключения к серверу или удалённому десктопу. Поэтому уязвимости вызывают определённое беспокойство. Тем более в нынешних условиях, когда весь трафик в интернете записывается и сохраняется в хранилищах провайдеров и хостеров. То есть в будущем его могут расшифровать, будь найдена уязвимость, подрывающая базовую криптографию. Опасную уязвимость нашли исследователи из Рурского университета в Бохуме. Атака получила название Terrapin (CVE-2023-48795). Правда, её вряд ли можно использовать именно на сохранённом трафике, потому что схема MiTM предусматривает подбор значений во время рукопожатия сервера и клиента. У злоумышленника должен быть доступ к каналу и возможность подменять пакеты.

    habr.com/ru/companies/globalsi

    #SSH #TunnelCrack #SSH3 #SSH2 #HTTP/3 #QUIC #VPN #LocalNet #ServerIP #TLS_13 #HTTP_Authorization #авторизация #OAuth_20 #OpenID #сканирование_портов #OpenSSH #MiTM #Terrapin

  8. Атака на SSH и взлом туннелей VPN

    SSH стал практически стандартом де-факто для подключения к серверу или удалённому десктопу. Поэтому уязвимости вызывают определённое беспокойство. Тем более в нынешних условиях, когда весь трафик в интернете записывается и сохраняется в хранилищах провайдеров и хостеров. То есть в будущем его могут расшифровать, будь найдена уязвимость, подрывающая базовую криптографию. Опасную уязвимость нашли исследователи из Рурского университета в Бохуме. Атака получила название Terrapin (CVE-2023-48795). Правда, её вряд ли можно использовать именно на сохранённом трафике, потому что схема MiTM предусматривает подбор значений во время рукопожатия сервера и клиента. У злоумышленника должен быть доступ к каналу и возможность подменять пакеты.

    habr.com/ru/companies/globalsi

    #SSH #TunnelCrack #SSH3 #SSH2 #HTTP/3 #QUIC #VPN #LocalNet #ServerIP #TLS_13 #HTTP_Authorization #авторизация #OAuth_20 #OpenID #сканирование_портов #OpenSSH #MiTM #Terrapin

  9. If you need to mitigate the #Terrapin attack against your SSH server (terrapin-attack.com/#scanner) and you can't simply update to a patched version I found this page helpful to prepare the sshd config and check your ssh client: bobcares.com/blog/how-to-disab
    Here is a description of what needs to be done: blog.rwth-aachen.de/itc-change
    Finally check your configuration with the scanner above and e.g. sshcheck.com/
    Most important: Don't make mistakes and lock yourself out. #1 check your recovery options!

  10. Buongiorno da @github che annuncia il suo programma di certificazioni (e un nuovo modo di generare i suoi SDK), e poi i server SSH non sono ancora stati patchati per Terrapin e ci sono nuovi round di layoff in Twitch e Unity.

    In intro la parola chiave sarà #enshittification.

    #github #terrapin #ssh #security #layoff #gaming

    youtube.com/watch?v=kDp5yimI8L

  11. Communing with turtles again, this time in the business park in Sydney where the AAO offices are.

    #reptile #turtle #terrapin

  12. Configuring SSH on AWS EC2 Amazon Linux Instances to Protect Against the Terrapin Attack
    ~~
    Patch OpenSSH — AND — Disallow insecure connections by removing them from your configuration
    ~~
    #Terrapin #AWS #SSH #Encryption #Downgrade #OpenSSH #Cybersecurity

    medium.com/cloud-security/conf

  13. Communed with the turtles at the lagoon earlier this evening.

    #reptile #turtle #terrapin

  14. thx @lambdafu, @Skrillor et al @ RUB for the excellent research on the [Terrapin Attack](terrapin-attack.com).

    The #Terrapin Scanner is available here:
    github.com/RUB-NDS/Terrapin-Sc

    For Your reference:

    - CVE-2023-48795: General Protocol Flaw
    - CVE-2023-46445: Rogue Extension Negotiation Attack in AsyncSSH
    - CVE-2023-46446: Rogue Session Attack in AsyncSSH

  15. In Deutschland könnten noch ca. 1 Million SSH-Server durch die #Terrapin-#Schwachstelle angreifbar sein. Um die eigene Verwundbarkeit zu überprüfen, stellen die Sicherheitsforschenden von
    @ruhrunibochum
    unter terrapin-attack.com ein Tool zur Verfügung.

  16. „Für all jene, die einen #SSH-Server betreiben, bieten die Forscher der Ruhr Universität Bochum, die #Terrapin im Dezember vorgestellt haben, auf Github einen Schwachstellen-Scanner an. Damit lässt sich die Anfälligkeit überprüfen.“

    golem.de/news/deutschland-auf-