Re: openssh
Rainer Peter Feller <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 4 Dec 2002, Dagmar d'Surreal wrote: > > You realize that while your patch may work, it won't stop them from > making connections out. Telnet can go to port 22 just fine, and there's > probably nothing stopping your users from building their own copy of > ssh, or bringing their own binary. If you _really_ want to stop > connections from going out to port 22 on those other interfaces, add > some drop rules to your iptables configuration--or better yet _secure > the hosts on those segments_. > Every binary is perfect under control ... they are not able to write to a filesystem where they an execute anything, there is no telnet or compiler. And yes there is a firewall. Why do you think I call it paranoia-patch ;-) H CUH Rainer Peter Feller H -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message