{"id":87197,"date":"2020-07-05T07:42:02","date_gmt":"2020-07-05T05:42:02","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-ssh-klientah-openssh-i-putty"},"modified":"2020-07-05T07:42:02","modified_gmt":"2020-07-05T05:42:02","slug":"uyazvimost-v-ssh-klientah-openssh-i-putty","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty","title":{"rendered":"Vulnerabilidad en los clientes SSH OpenSSH y PuTTY","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>En los clientes SSH OpenSSH y PuTTY <noindex><a rel=\"nofollow\" href=\"https:\/\/www.fzi.de\/en\/news\/news\/detail-en\/artikel\/fsa-2020-2-ausnutzung-eines-informationslecks-fuer-gezielte-mitm-angriffe-auf-ssh-clients\/\">se ha detectado<\/a><\/noindex> <noindex><a rel=\"nofollow\" href=\"https:\/\/www.fzi.de\/fileadmin\/user_upload\/2020-06-26-FSA-2020-2.pdf\">vulnerabilidad<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-14002\">CVE-2020-14002<\/a><\/noindex> en PuTTY y <noindex><a rel=\"nofollow\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-14145\">CVE-2020-14145<\/a><\/noindex> en OpenSSH), que lleva a la filtraci\u00f3n de informaci\u00f3n en el algoritmo de negociaci\u00f3n de conexi\u00f3n. La vulnerabilidad permite a un atacante, capaz de interceptar el tr\u00e1fico del cliente (por ejemplo, al conectar a un usuario a trav\u00e9s de un punto de acceso inal\u00e1mbrico controlado por el atacante), identificar el intento de conexi\u00f3n inicial del cliente al host, cuando a\u00fan no se ha guardado en cach\u00e9 la clave del host. <\/p>\n<p>Sabiendo que el cliente intenta conectarse por primera vez y a\u00fan no tiene la clave del host, el atacante puede retransmitir la conexi\u00f3n a trav\u00e9s de s\u00ed mismo (MITM) y entregar al cliente su clave de host, que el cliente SSH considerar\u00e1 como la clave del host objetivo, a menos que realice una verificaci\u00f3n de huellas digitales de la clave. De esta forma, el atacante puede llevar a cabo un MITM sin suscitar sospechas en el usuario e ignorar las sesiones en las que el cliente ya tiene claves de host guardadas en cach\u00e9, ya que un intento de reemplazo de estas generar\u00e1 una advertencia sobre el cambio de clave del host. El ataque se basa en la negligencia de los usuarios que no realizan la verificaci\u00f3n manual de la huella digital de la clave del host en su primera conexi\u00f3n. Aquellos que comprueban las huellas de las claves est\u00e1n protegidos contra ataques similares.<\/p>\n<p>Como un indicador para determinar el primer intento de conexi\u00f3n se utiliza el cambio en el orden de enumeraci\u00f3n de los algoritmos de claves de host admitidos. En caso de que se produzca la primera conexi\u00f3n, el cliente env\u00eda una lista de algoritmos por defecto, y si la clave del host ya est\u00e1 en cach\u00e9, el algoritmo asociado se coloca en primer lugar (los algoritmos se ordenan por preferencia). <\/p>\n<p>El problema se manifiesta en las versiones de OpenSSH desde 5.7 hasta 8.3 y en PuTTY desde 0.68 hasta 0.73. El problema <noindex><a rel=\"nofollow\" href=\"https:\/\/git.tartarus.org\/?p=simon\/putty.git;a=commit;h=08f1e2a5066ea95559945af339a60ca14560d764\">se solucion\u00f3<\/a><\/noindex> en la versi\u00f3n <noindex><a rel=\"nofollow\" href=\"https:\/\/lists.tartarus.org\/pipermail\/putty-announce\/2020\/000030.html\">PuTTY 0.74<\/a><\/noindex> a trav\u00e9s de la adici\u00f3n de una opci\u00f3n para desactivar la construcci\u00f3n din\u00e1mica de la lista de algoritmos de procesamiento de claves de host en favor de enumerar los algoritmos en un orden fijo.<\/p>\n<p>El proyecto OpenSSH no tiene planes de cambiar el comportamiento del cliente SSH, ya que si no se especifica el algoritmo de la clave existente primero, se intentar\u00e1 aplicar un algoritmo que no coincide con la clave en cach\u00e9, mostrando una advertencia sobre una clave desconocida. Es decir, surge una elecci\u00f3n: o una fuga de informaci\u00f3n (OpenSSH y PuTTY), o la emisi\u00f3n de advertencias sobre el cambio de clave (Dropbear SSH) en caso de que la clave guardada no coincida con el primer algoritmo en la lista por defecto.<\/p>\n<p>Para garantizar la seguridad en OpenSSH, se sugiere utilizar m\u00e9todos alternativos para verificar la clave del host mediante registros SSHFP en DNSSEC y certificados de host (PKI). Tambi\u00e9n se puede desactivar la selecci\u00f3n adaptativa de algoritmos de claves de host a trav\u00e9s de la opci\u00f3n HostKeyAlgorithms y utilizar la opci\u00f3n UpdateHostKeys para que el cliente obtenga claves adicionales del host despu\u00e9s de la autenticaci\u00f3n.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fuente: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53286\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2020-14002 \u0432 PuTTY \u0438 CVE-2020-14145 \u0432 OpenSSH), \u043f\u0440\u0438\u0432\u043e\u0434\u044f\u0449\u0430\u044f \u043a \u0443\u0442\u0435\u0447\u043a\u0435 \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u0439 \u0432 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0435 \u0441\u043e\u0433\u043b\u0430\u0441\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u043e\u0435\u0434\u0438\u043d\u0435\u043d\u0438\u044f. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443, \u0441\u043f\u043e\u0441\u043e\u0431\u043d\u043e\u043c\u0443 \u043f\u0435\u0440\u0435\u0445\u0432\u0430\u0442\u0438\u0442\u044c \u0442\u0440\u0430\u0444\u0438\u043a \u043a\u043b\u0438\u0435\u043d\u0442\u0430 (\u043d\u0430\u043f\u0440\u0438\u043c\u0435\u0440, \u043f\u0440\u0438 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0447\u0435\u0440\u0435\u0437 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u0438\u0440\u0443\u0435\u043c\u0443\u044e \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0438\u043c \u0442\u043e\u0447\u043a\u0443 \u0431\u0435\u0441\u043f\u0440\u043e\u0432\u043e\u0434\u043d\u043e\u0433\u043e \u0434\u043e\u0441\u0442\u0443\u043f\u0430), \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0438\u0442\u044c \u043f\u043e\u043f\u044b\u0442\u043a\u0443 \u043f\u0435\u0440\u0432\u043e\u043d\u0430\u0447\u0430\u043b\u044c\u043d\u043e\u0433\u043e \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0435\u043d\u0438\u044f \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u043a \u0445\u043e\u0441\u0442\u0443, \u043a\u043e\u0433\u0434\u0430 \u043a\u043b\u0438\u0435\u043d\u0442\u043e\u043c \u0435\u0449\u0451 \u043d\u0435 \u043f\u0440\u043e\u043a\u044d\u0448\u0438\u0440\u043e\u0432\u0430\u043d \u043a\u043b\u044e\u0447 \u0445\u043e\u0441\u0442\u0430. \u0417\u043d\u0430\u044f, \u0447\u0442\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-87197","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-07-05T05:42:02+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-07-05T05:42:02+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilidad en los clientes SSH OpenSSH y PuTTY | ProHoster","description":"En los clientes SSH OpenSSH y PuTTY","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY | ProHoster","og:description":"\u0412 SSH-\u043a\u043b\u0438\u0435\u043d\u0442\u0430\u0445 OpenSSH \u0438 PuTTY","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/uyazvimost-v-ssh-klientah-openssh-i-putty","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-07-05T05:42:02+00:00","article:modified_time":"2020-07-05T05:42:02+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"87197","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 13:56:23","updated":"2022-10-07 22:11:57","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/87197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=87197"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/87197\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=87197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=87197"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=87197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}