<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[A 27-Year-Old Authentication Bypass in OpenBSD&#x27;s PPP Stack]]></title><description><![CDATA[<blockquote>
<p dir="auto">OpenBSD's sppp_pap_input function used attacker-controlled length fields as the bcmp comparison length for credential validation. Sending zero-length name and password fields caused bcmp to return 0 unconditionally, bypassing PAP authentication entirely. The vulnerability was introduced in 1999 and survived for 27 years before being fixed.</p>
</blockquote>
<ul>
<li><a href="https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html" rel="nofollow ugc">https://blog.argus-systems.ai/blog/openbsd-pap-27-year-auth-bypass.html</a></li>
</ul>
]]></description><link>https://billboard.bsd.cafe/topic/254/a-27-year-old-authentication-bypass-in-openbsd-s-ppp-stack</link><generator>RSS for Node</generator><lastBuildDate>Wed, 17 Jun 2026 18:55:57 GMT</lastBuildDate><atom:link href="https://billboard.bsd.cafe/topic/254.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 17 Jun 2026 06:57:27 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to A 27-Year-Old Authentication Bypass in OpenBSD&#x27;s PPP Stack on Wed, 17 Jun 2026 17:09:45 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">… The code originated from FreeBSD, which itself derived it from Cronyx Engineering Ltd.'s implementation written by Serge Vakulenko in 1994-1996. …</p>
</blockquote>
<p dir="auto">I assume that FreeBSD is not affected.</p>
]]></description><link>https://billboard.bsd.cafe/post/707</link><guid isPermaLink="true">https://billboard.bsd.cafe/post/707</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Wed, 17 Jun 2026 17:09:45 GMT</pubDate></item></channel></rss>