Re: openssh

Dagmar d'Surreal <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Fri, 2002-12-06 at 04:36, Rainer Peter Feller wrote:
> On Fri, 6 Dec 2002, Daniel Roethlisberger wrote:
> 
> > ahem.. what the heck is wrong with setting up netfilter to drop outgoing
> > ssh traffic on those ifaces? that's a matter of issueing a small number
> > of iptables commands. why don't you do it the easy way? (locking down
> > the system does make sense sometimes, but not merely to stop users from
> > ssh'ing through certain ifaces.
> >
> > cheers
> > dan (puzzled, I dare say)
> 
> nothing is wrong with iptables, that is why I use them, but I am araid
> that they are not enough.
> 
> ssh'ing to a special interface speeds up the connection, cause they can
> build tunnel which will go in from eth1 and go out to eth0.

More and more it sounds like you need to use restricted shell accounts
instead of allowing the users to run whatever commands they want.  Or
better yet, since the users don't seem to be able to do much of anything
anyway, _disable_ their shell accounts entirely.  Speeds up their
connection, indeed.

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.