FirstHackers News’ Post

View profile for FirstHackers News, graphic

News Specialist at FirstHackersNews-India

Security researchers have published a Proof-of-Concept (PoC) exploit for a critical vulnerability in the widely used PuTTY SSH and Telnet client. The flaw, CVE-2024-31497, permits attackers to recover private keys generated with the NIST P-521 elliptic curve in PuTTY versions 0.68 through 0.80. This vulnerability arises from PuTTY’s biased generation of ECDSA nonces when using the P-521 curve. Researchers discovered that the first 9 bits of each nonce are consistently zero, allowing for full private key recovery from approximately 60 signatures using lattice cryptanalysis techniques. Security researcher Hugo Bond demonstrated the attack’s feasibility by publishing a PoC exploit on GitHub. Leveraging the nonce bias, the PoC recovers the private key from a set of signatures generated by a vulnerable PuTTY version. ~First Hackers News To Continue reading this article, click on this link >>> https://lnkd.in/eByKXvrE #securityresearchers #PoC #vulnerability #telnet #attackers #privatekey #cryptanalysis #PuTTY #cyberattack #cybersecurity #fhn #firsthackersnews #informationsecurity #latestnews

Proof-of-Concept (PoC) Released for Critical PuTTY Private Key Recovery Vulnerability

Proof-of-Concept (PoC) Released for Critical PuTTY Private Key Recovery Vulnerability

https://firsthackersnews.com

To view or add a comment, sign in

Explore topics