Re: openssh

Dagmar d'Surreal <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Thu, 2002-12-05 at 10:58, Rainer Peter Feller wrote:
> On Thu, 5 Dec 2002, Dagmar d'Surreal wrote:
> 
> > Paranoia is an unbalanced mental state.  Unbalanced mental states lead
> > to error.  I'd almost be willing to bet money that you didn't remove
> > perl from the system, and that would be a mistake.  It's a good thing
> > you have outbound connections to dst port 22 blocked in your firewalling
> > rules.
> 
> O.K. I expect you want to know ...
> even if you don't :-)

You're right.  I don't.  ...and just because I cited one specific
example doesn't mean that's the _only_ probable flaw in play.  I can
come up with many, many more questionable things than the one mentioned
(why not restricted shell for user accounts?  why do you even have man
pages installed on this thing?) ...and I still think that for the
purpose you cited, your modification to ssh is fairly useless.  What I'm
trying to make clear to you is that there is _far_ more to hardening a
system than just what you've done, and (although I dread repeating
myself, to make this crystal clear) your time would have been much
better spent doing a number of things other than making those kinds of
modifications to ssh.

In short, neither the universe nor script kiddies will give you points
for extra effort.

> The environment we talk about is a chrooted one, there is a sshd on the
> wild which accepts connections from everywhere.
> 
(useless info snipped)
> 
> not more
> the user root can't logon ...

So you've protected the system against malicious users who know the root
password.  It's a shame that most crackers never need it.

> where the user can write he can't exec or use devices ... so simple

Your ability to post skeletal details about your system is not going to
make me or anyone else think that the system is as secure as you
apparently think it is.  Nor should it matter to them.  But hey, you're
certainly never going to *know* your system's been compromised, since
you apparently don't even have so much as a single syslogd
implementation installed, let alone some kind of integrity checker (like
tripwire), or crond to regularly redo those checks, or tcp wrappers so
that you can implement rudimentary protection from evil-doers for your
sshd that's running "in the wild", or anything like the grsecurity patch
to the kernel (_super_ nice), or the pro-police patch IBM made (OMG it
rocks) for gcc to hinder various stack-overflow techniques.

(p.s. I will admit that such a patch could be useful for other things,
but is pretty pointless for the purpose initially described)


-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.