OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Fw: [suse-security] sftp with no ssh login

From: Sven 'Darkman' Michels (svendarkman.de)
Date: Wed Jan 28 2004 - 14:22:06 CST


Manuel Balderrábano wrote:
> Hi to all again, thanks for all the ideas!
>
> What I did at the end is a mix of some things you guys said:
>
> 1.- created a .bashrc fila with a logout on the first line for all users
> (Just one)
> 2.- Change shell to bash for all this users.
> 3.- chown root .bashrc
> 4.- chmod 555 .bashrc
>
> And there you go!
>
> Do you find a hole on that?

how about this:

ssh remote.host /bin/sash

;)

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here