Re: OpenSSH keyboard-interactive authentication brute force vulnerability (MaxAuthTries bypass)

Posted by Dirk-Willem van Gulik on Jul 21

Arguably the question then should be to have a MaxChallengeTries as an analog of MaxAuthTries – and perhaps by default
set MaxChallengeTries to the same (sane) value of MaxAuthTries.

Dw.

Leave a Reply