Re: openssh

Rainer Peter Feller <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Wed, 4 Dec 2002, Dagmar d'Surreal wrote:
>
> You realize that while your patch may work, it won't stop them from
> making connections out.  Telnet can go to port 22 just fine, and there's
> probably nothing stopping your users from building their own copy of
> ssh, or bringing their own binary.  If you _really_ want to stop
> connections from going out to port 22 on those other interfaces, add
> some drop rules to your iptables configuration--or better yet _secure
> the hosts on those segments_.
>

Every binary is perfect under control ... they are not able to write to a
filesystem where they an execute anything, there is no telnet or
compiler.
And yes there is a firewall.

Why do you think I call it paranoia-patch ;-)

  H
CUH Rainer Peter Feller
  H


-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.