Re: openssh
Dagmar d'Surreal <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 2002-12-05 at 10:58, Rainer Peter Feller wrote: > On Thu, 5 Dec 2002, Dagmar d'Surreal wrote: > > > Paranoia is an unbalanced mental state. Unbalanced mental states lead > > to error. I'd almost be willing to bet money that you didn't remove > > perl from the system, and that would be a mistake. It's a good thing > > you have outbound connections to dst port 22 blocked in your firewalling > > rules. > > O.K. I expect you want to know ... > even if you don't :-) You're right. I don't. ...and just because I cited one specific example doesn't mean that's the _only_ probable flaw in play. I can come up with many, many more questionable things than the one mentioned (why not restricted shell for user accounts? why do you even have man pages installed on this thing?) ...and I still think that for the purpose you cited, your modification to ssh is fairly useless. What I'm trying to make clear to you is that there is _far_ more to hardening a system than just what you've done, and (although I dread repeating myself, to make this crystal clear) your time would have been much better spent doing a number of things other than making those kinds of modifications to ssh. In short, neither the universe nor script kiddies will give you points for extra effort. > The environment we talk about is a chrooted one, there is a sshd on the > wild which accepts connections from everywhere. > (useless info snipped) > > not more > the user root can't logon ... So you've protected the system against malicious users who know the root password. It's a shame that most crackers never need it. > where the user can write he can't exec or use devices ... so simple Your ability to post skeletal details about your system is not going to make me or anyone else think that the system is as secure as you apparently think it is. Nor should it matter to them. But hey, you're certainly never going to *know* your system's been compromised, since you apparently don't even have so much as a single syslogd implementation installed, let alone some kind of integrity checker (like tripwire), or crond to regularly redo those checks, or tcp wrappers so that you can implement rudimentary protection from evil-doers for your sshd that's running "in the wild", or anything like the grsecurity patch to the kernel (_super_ nice), or the pro-police patch IBM made (OMG it rocks) for gcc to hinder various stack-overflow techniques. (p.s. I will admit that such a patch could be useful for other things, but is pretty pointless for the purpose initially described) -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message