blob: 8a567c2e84acd319499152eeb7941d1b71c67027 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
|
Current:
Things which need doing:
- Make options.h generated from configure perhaps?
- investigate self-pipe?
- fix agent fwd problems
- improve channel window adjustment algorithm (circular buffering)
- Don't use pregenerated AES tables
- check PRNG
- check that there aren't timing issues with valid/invalid user authentication
feedback.
- IP6 (binding to :: takes over ipv4 as well, sigh. If anyone wants to suggest
a clean way (ie no V4MAPPED or setsockopt things) please let me know :)
- Binding to different interfaces (see ipv6 probably)
- PAM ??
- inetd
- possible RSA blinding? need to check whether this is vuln to timing attacks
- CTR mode, SSH_MSG_IGNORE sending to improve CBC security
- DH Group Exchange possibly
- Use m_burn for clearing sensitive items in LTM/LTC
- fix scp.c for IRIX
|