<freeStyleBuild _class='hudson.model.FreeStyleBuild'><action _class='hudson.model.CauseAction'><cause _class='hudson.triggers.SCMTrigger$SCMTriggerCause'><shortDescription>Started by an SCM change</shortDescription></cause></action><action></action><action _class='hudson.plugins.git.util.BuildData'><buildsByBranchName><refsremotesoriginoihipster _class='hudson.plugins.git.util.Build'><buildNumber>4147</buildNumber><marked><SHA1>43616c8731a48eff82ca79506d41e2b1e3f90baf</SHA1><branch><SHA1>43616c8731a48eff82ca79506d41e2b1e3f90baf</SHA1><name>refs/remotes/origin/oi/hipster</name></branch></marked><revision><SHA1>43616c8731a48eff82ca79506d41e2b1e3f90baf</SHA1><branch><SHA1>43616c8731a48eff82ca79506d41e2b1e3f90baf</SHA1><name>refs/remotes/origin/oi/hipster</name></branch></revision></refsremotesoriginoihipster><originHEAD _class='hudson.plugins.git.util.Build'><buildNumber>2</buildNumber><marked><SHA1>a248aeece198193fec99eba994911716ef449c73</SHA1><branch><SHA1>a248aeece198193fec99eba994911716ef449c73</SHA1><name>origin/oi/hipster</name></branch><branch><SHA1>a248aeece198193fec99eba994911716ef449c73</SHA1><name>origin/HEAD</name></branch></marked><revision><SHA1>a248aeece198193fec99eba994911716ef449c73</SHA1><branch><SHA1>a248aeece198193fec99eba994911716ef449c73</SHA1><name>origin/oi/hipster</name></branch><branch><SHA1>a248aeece198193fec99eba994911716ef449c73</SHA1><name>origin/HEAD</name></branch></revision></originHEAD><originoihipster _class='hudson.plugins.git.util.Build'><buildNumber>1129</buildNumber><marked><SHA1>cfc2a57e0553acffbe03c3f54f24cadaac25e1b7</SHA1><branch><SHA1>cfc2a57e0553acffbe03c3f54f24cadaac25e1b7</SHA1><name>origin/oi/hipster</name></branch></marked><revision><SHA1>cfc2a57e0553acffbe03c3f54f24cadaac25e1b7</SHA1><branch><SHA1>cfc2a57e0553acffbe03c3f54f24cadaac25e1b7</SHA1><name>origin/oi/hipster</name></branch></revision></originoihipster></buildsByBranchName><lastBuiltRevision><SHA1>43616c8731a48eff82ca79506d41e2b1e3f90baf</SHA1><branch><SHA1>43616c8731a48eff82ca79506d41e2b1e3f90baf</SHA1><name>refs/remotes/origin/oi/hipster</name></branch></lastBuiltRevision><remoteUrl>git://github.com/OpenIndiana/oi-userland.git</remoteUrl><scmName></scmName></action><action _class='hudson.plugins.git.GitTagAction'></action><action></action><action _class='org.jenkinsci.plugins.displayurlapi.actions.RunDisplayAction'><artifactsUrl>https://hipster.openindiana.org/jenkins/job/oi-userland/4147/artifact</artifactsUrl><changesUrl>https://hipster.openindiana.org/jenkins/job/oi-userland/changes</changesUrl><displayUrl>https://hipster.openindiana.org/jenkins/job/oi-userland/4147/</displayUrl><testsUrl>https://hipster.openindiana.org/jenkins/job/oi-userland/4147/testReport</testsUrl></action><building>false</building><displayName>#4147</displayName><duration>1310451</duration><estimatedDuration>1266995</estimatedDuration><fullDisplayName>oi-userland #4147</fullDisplayName><id>4147</id><inProgress>false</inProgress><keepLog>false</keepLog><number>4147</number><queueId>2313</queueId><result>SUCCESS</result><timestamp>1535277007328</timestamp><url>https://hipster.openindiana.org/jenkins/job/oi-userland/4147/</url><builtOn></builtOn><changeSet _class='hudson.plugins.git.GitChangeSetList'><item _class='hudson.plugins.git.GitChangeSet'><affectedPath>components/network/openssh/Makefile</affectedPath><affectedPath>components/network/openssh/patches/CVE-2018-15473.patch</affectedPath><commitId>43616c8731a48eff82ca79506d41e2b1e3f90baf</commitId><timestamp>1535276343000</timestamp><author><absoluteUrl>https://hipster.openindiana.org/jenkins/user/wacki</absoluteUrl><fullName>Andreas Wacknitz</fullName></author><authorEmail>A.Wacknitz@gmx.de</authorEmail><comment>OpenSSH: fix CVE-2018-15473 (username enumeration)
Fix from OpenSSH 7.8p1 (https://www.openssh.com/releasenotes.html):
```
* sshd(8): add some countermeasures against timing attacks used for
  account validation/enumeration. sshd will enforce a minimum time
  or each failed authentication attempt consisting of a global 5ms
  minimum plus an additional per-user 0-4ms delay derived from a
  host secret.
```
 Debian patch:
https://sources.debian.org/patches/openssh/1:7.4p1-10+deb9u4/upstream-delay-bailout-for-invalid-authenticating-user.patch/


**Testing (exploit: https://www.exploit-db.com/exploits/45210/)**
 Affected:
```
$ python 45210.py 192.168.1.12 root
[+] Valid username

$ python 45210.py 192.168.1.12 thisisinvalid
[*] Invalid username
```
 Fixed:
```
$ python 45210.py 192.168.1.181 root
[+] Valid username

$ python 45210.py 192.168.1.181 thisisinvalid
[+] Valid username
```
</comment><date>2018-08-26 11:39:03 +0200</date><id>43616c8731a48eff82ca79506d41e2b1e3f90baf</id><msg>OpenSSH: fix CVE-2018-15473 (username enumeration)</msg><path><editType>add</editType><file>components/network/openssh/patches/CVE-2018-15473.patch</file></path><path><editType>edit</editType><file>components/network/openssh/Makefile</file></path></item><kind>git</kind></changeSet><culprit><absoluteUrl>https://hipster.openindiana.org/jenkins/user/a.wacknitz</absoluteUrl><fullName>A.Wacknitz</fullName><id>a.wacknitz</id></culprit></freeStyleBuild>