public inbox for cygwin@cygwin.com
 help / color / mirror / Atom feed
* No this has a nasty bite
@ 2000-05-26 10:45 Prentis Brooks
  2000-05-27 14:35 ` [ANNOUNCEMENT]: patched openSSH-1.2.2 [was Re: No this has a nasty bite] Corinna Vinschen
  0 siblings, 1 reply; 7+ messages in thread
From: Prentis Brooks @ 2000-05-26 10:45 UTC (permalink / raw)
  To: Cygwin

Alright, this is a problem... Corinna, if you happen to have a quick
solution before I start trying to dig around in the source, please let me
know.

Here is the problem:

You have RSA Authentication enabled and running as user foo on port 22.  You
have another Daemon running SSH with password authentication on port 26.  If
user bar sets up RSA keys in his/her home directory and then connects to
port 22, it will authenticate him/her via the keys in bar's home directory
and then promptly drop them to the shell as foo... this is bad.


Any ideas on how to:

1) Identify who the RSA enabled process is running under
2) Once one is known, ensure that the user coming in is the user we are
running under, rejecting if not.

Prentis


--
Want to unsubscribe from this list?
Send a message to cygwin-unsubscribe@sourceware.cygnus.com

^ permalink raw reply	[flat|nested] 7+ messages in thread
[parent not found: <s048jsc0d8a3j88k2r57mkkbs21qbac6jo@4ax.com>]

end of thread, other threads:[~2000-05-30 12:20 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2000-05-26 10:45 No this has a nasty bite Prentis Brooks
2000-05-27 14:35 ` [ANNOUNCEMENT]: patched openSSH-1.2.2 [was Re: No this has a nasty bite] Corinna Vinschen
2000-05-27 20:58   ` Prentis Brooks
2000-05-28  2:52     ` Corinna Vinschen
2000-05-30 11:19       ` Prentis Brooks
2000-05-30 12:20         ` Corinna Vinschen
     [not found] <s048jsc0d8a3j88k2r57mkkbs21qbac6jo@4ax.com>
2000-05-30 12:11 ` Prentis Brooks

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).