security of scponly/sftp-server in combination with apacheTrackbacks
Trackback specific URI for this entry
No Trackbacks
Comments
Display comments as
(Linear | Threaded)
Lack of proper HTML escaping caused (apropos to a post about easily making errors) ate your example problematic PHP.
Im using sftp with chroot and it works pretty good
http://www.debian-administration.org/articles/590 If you have a lot of users you cant trust everyone
You do not need apache and php. Most system have a MTA installed. And most MTAs by default allow some things in .forward that makes only allowing sftp a bit mood.
At least with mod_suexec you can ensure that their shell will run as them, and not as www-data.
well sure, that's why I wrote "standard setup". This is also just a dirty workaround, what if the webserver serves cgis? I think instead of this everyone would probably just chroot this.
Hmm.. firewall? At a minimum on a production server, you should probably be dropping packets not on expected ports.. doesn't fix much, but it'll rule out nc as an attack vector.
Of course, if they can system() arbitrary commands, lack of a shell will hardly prevent a malicious user from causing mischief..
that limits the nc vector, still you can also setup a connect back shell.... of course there is always a way to prevent that, this post is just to point out one thing you have to think of when setting this up, nothing more...
Add Comment
|
CalendarQuicksearchSupportRecent Entriesprotocol design fail: MMS notification
Wednesday, July 28 2010 acrobat reader stealing my passwords Tuesday, June 29 2010 UnrealIRCd backdoored Saturday, June 12 2010 fail of the day: opera Wednesday, June 9 2010 fail2ban + dns = fail Wednesday, May 26 2010 evolution of spam or WTF is this! Friday, March 19 2010 if you type google into google... Wednesday, March 17 2010 Two weeks with the n900 Monday, February 8 2010 Chomsky garden gnome Wednesday, December 23 2009 wikileaks released 9/11 pager messages Thursday, November 26 2009 CategoriesTag cloud23c3 acpi advertising annouce announce april argh art awards bash blogging browser bugs cli code config configuration copyright data mining debconf debian dell dns documentation email errm? events fail fail2ban filesharing films flame fun gcc google graphs grml hacking hacks hardware heise images information internet irc knowledge libacpi links linux mail monitoring network networking news newsbeuter nonsense omg openoffice open source opera passwords phrack piratebay privacy programming qa random blurb rant release releases rss scripts security service setup shell software spam ssh stfl stuff terminal tests text mode tip tips tools troubleshooting unix user video vim.editing web web 2.0 websites wordpress wtf www youtube zsh
|