Re: openssh
Rainer Peter Feller <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Fri, 6 Dec 2002, Dagmar d'Surreal wrote: > More and more it sounds like you need to use restricted shell accounts > instead of allowing the users to run whatever commands they want. Or > better yet, since the users don't seem to be able to do much of anything > anyway, _disable_ their shell accounts entirely. Speeds up their > connection, indeed. Hm ... restricted shell ... I am afraid that's not what they want to have. My problem is that, on one hand, my customers (all other people of my institute) do not want the whole stuff too complicate. On the other hand, I don't want someone who got somehow into the system easy to screw up my network. My problem is not the "normal" user, but some script kiddies which got a password by installing a patched ssh-client on an untrusted host. H CUH Rainer Peter Feller H -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message