‹ BackHN Continuity

Thread

Show HN: ssh ssh.place

184 points · 120 comments · jeninh

  1. 3dedb728-3f77 · · focus · HN ↗
    Hey, is it not just a simple honeypot reverse hack ssh server?

    People understand that reverse hacking can happen when connecting to random ssh server, right?

    1. scubbo · · focus · HN ↗
      > People understand that reverse hacking can happen when connecting to random ssh server, right?

      No, actually, I've never heard of such a vector. How would that work?

      1. mr_mitm · · focus · HN ↗
        Here is a recent example. Currently unpatched in Debian stable.

        <a href="https:&#x2F;&#x2F;www.cve.org&#x2F;CVERecord?id=CVE-2026-60002" rel="nofollow">https:&#x2F;&#x2F;www.cve.org&#x2F;CVERecord?id=CVE-2026-60002

        As I understood this, a malicious server can change its host key somewhere during key exchange and trigger a use-after-free in the client, which might be exploitable for code execution.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.