Re: openssh

Scot Mc Pherson <[email protected]>
Newsgroups gmane.linux.lfs.security
Organization Linux From Scratch
Message-ID <[email protected]>
On Mon, 09 Dec 2002 12:24:00 -0500, Dagmar d'Surreal wrote:

> On Mon, 2002-12-09 at 02:22, Rainer Peter Feller wrote:
>> On Fri, 6 Dec 2002, Dagmar d'Surreal wrote:
>> 
>> > More and more it sounds like you need to use restricted shell
>> > accounts instead of allowing the users to run whatever commands they
>> > want.  Or better yet, since the users don't seem to be able to do
>> > much of anything anyway, _disable_ their shell accounts entirely.
>> > Speeds up their connection, indeed.
>> 
>> Hm ... restricted shell ... I am afraid that's not what they want to
>> have. My problem is that, on one hand, my customers (all other people
>> of my institute) do not want the whole stuff too complicate.
> 
> A restricted shell does not make things more complicated for users.
> Everything looks the same to them, aside from they only get to run a
> very small list of commands.
> 
>> On the other hand, I don't want someone who got somehow into the system
>> easy to screw up my network. My problem is not the "normal" user, but
>> some script kiddies which got a password by installing a patched
>> ssh-client on an untrusted host.
> 
> ...then you need a restricted shell, *and* everything I mentioned in
> that other post, especially the pro-police patch for gcc, and the
> grsecurity patch.
 
the largest restriction users will ntoice is not eing able to cd into
another directory

Scot
-- 
Unsubscribe: send email to [email protected]
and put 'unsubscribe lfs-security' in the subject header of the message
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.