Re: [Full-disclosure] OpenSSH 3.5p1 Remote Root Exploit for FreeBSD

This seems to be in libopie rather than sshd or libpam and happens
when the username is longer than OPIE_PRINCIPAL_MAX.  I'm not sure
exactly where inside libopie it is, but commenting out pam_opie.so
seems to prevent it.

prevents usernames longer than OPIE_PRINCIPAL_MAX from being accepted
by pam_opie.

