Re: openssh

Dagmar d'Surreal <[email protected]>
Newsgroups gmane.linux.lfs.security
Message-ID <[email protected]>
On Mon, 2002-12-09 at 02:22, Rainer Peter Feller wrote:
> On Fri, 6 Dec 2002, Dagmar d'Surreal wrote:
> 
> > More and more it sounds like you need to use restricted shell accounts
> > instead of allowing the users to run whatever commands they want.  Or
> > better yet, since the users don't seem to be able to do much of anything
> > anyway, _disable_ their shell accounts entirely.  Speeds up their
> > connection, indeed.
> 
> Hm ... restricted shell ... I am afraid that's not what they want to have.
> My problem is that, on one hand, my customers (all other people of my
> institute) do not want the whole stuff too complicate.

A restricted shell does not make things more complicated for users. 
Everything looks the same to them, aside from they only get to run a
very small list of commands.

> On the other hand, I don't want someone who got somehow into the system
> easy to screw up my network. My problem is not the "normal" user, but some
> script kiddies which got a password by installing a patched ssh-client on
> an untrusted host.

...then you need a restricted shell, *and* everything I mentioned in
that other post, especially the pro-police patch for gcc, and the
grsecurity patch.

-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.