STEL: Secure TELnet
David Vincenzetti, Stefano Taino, Fabio Bolognesi · 1995
Eavesdropping is becoming rampant on the Internet. We, as CERT-IT, have recorded a great number of sniffing attacks in the Italian community. In fact, sniffing is the most popular hacker's attack technique all over the Internet. This paper presents a secure telnet implementation which has been designed by the Italian CERT, to make eavesdropping ineffective to remote terminal sessions. It is not to be considered as a definitive solution but rather as a "bandaid" solution, to deal with one of the most serious security threats of the moment. 2. Introduction STEL stands for Secure TELnet. We started developing STEL, at the University of Milan, when we realized that eavesdropping was a very serious problem and we did not like the freeware solutions that were available at that time. It was about three years ago. Still, as far as we know, there are no really satisfying packages able to solve the line active and passive tapping problem, and to be simple enough to use and to maintain by the av...