cURL / Mailing Lists / curl-library / Single Mail


Re: curl+sftp+man-in-the-middle-attck.

From: Daniel Stenberg <>
Date: Fri, 14 Mar 2014 13:55:04 +0100 (CET)

On Fri, 14 Mar 2014, san d wrote:

>> sftp is vulnerable to man-in-the-middle attack.
> At least if there is way to retrieve the remote host key.

So you're top-posting on a reply to yourself about a fictious attack that you
don't describe?

Are you saying that SFTP in itself allows a MITM attack somehow? Please be
more specicific of where you say libcurl has a such problem. Also, bear in
mind that we try to keep security related problems non-public to keep users
safe until we fix and disclose them:

> Does the connection establishment/negotiation happen every call to
> curl_easy_perform()?

Unless it can re-use an existing connection, yes.

List admin:
Received on 2014-03-14