Re: openssh
Dagmar d'Surreal <[email protected]>
| Newsgroups | gmane.linux.lfs.security |
|---|---|
| Message-ID | <[email protected]> |
On Mon, 2002-12-09 at 02:22, Rainer Peter Feller wrote: > On Fri, 6 Dec 2002, Dagmar d'Surreal wrote: > > > More and more it sounds like you need to use restricted shell accounts > > instead of allowing the users to run whatever commands they want. Or > > better yet, since the users don't seem to be able to do much of anything > > anyway, _disable_ their shell accounts entirely. Speeds up their > > connection, indeed. > > Hm ... restricted shell ... I am afraid that's not what they want to have. > My problem is that, on one hand, my customers (all other people of my > institute) do not want the whole stuff too complicate. A restricted shell does not make things more complicated for users. Everything looks the same to them, aside from they only get to run a very small list of commands. > On the other hand, I don't want someone who got somehow into the system > easy to screw up my network. My problem is not the "normal" user, but some > script kiddies which got a password by installing a patched ssh-client on > an untrusted host. ...then you need a restricted shell, *and* everything I mentioned in that other post, especially the pro-police patch for gcc, and the grsecurity patch. -- Unsubscribe: send email to [email protected] and put 'unsubscribe lfs-security' in the subject header of the message