nanog mailing list archives
Re: Cisco says attacks are due to operational practices
From: "Stephen Sprunk" <ssprunk () cisco com>
Date: Fri, 11 Feb 2000 17:56:23 -0600
After a quick (<30 sec) trip to the man page, voila! To use non-privileged ports, add to /etc/config or ~/.ssh/config: Host * RhostsAuthentication no RhostsRSAAuthentication no UsePrivilegedPort no This disables attempting rhosts-style authentication, which any sane server should reject anyways. Why these are still enabled by default escapes me. S | | Stephen Sprunk, K5SSS, CCIE #3723 :|: :|: NSA, Network Consulting Engineer :|||: :|||: 14875 Landmark Blvd #400; Dallas, TX .:|||||||:..:|||||||:. Pager: 800-365-4578 / 800-901-6078 C I S C O S Y S T E M S Email: ssprunk () cisco com ----- Original Message ----- From: adrian () creative net au To: nanog () merit edu Sent: Friday, February 11, 2000 13:07 Subject: Re: Cisco says attacks are due to operational practices Its not a bug, its a leftover from rsh days - if the connection originates from a port below 1024, you could assume *cough* that the credentials the connection supplies are authentic, since the process needs to be root to bind to ports < 1024. This isn't a "but thats flawed!" discussion seed, take that to bugtraq. There's a flag to ssh somewhere to stop it doing that. Yup, -P . Adrian
Current thread:
- Re: Cisco says attacks are due to operational practices, (continued)
- Re: Cisco says attacks are due to operational practices Majdi S. Abbas (Feb 10)
- Re: Cisco says attacks are due to operational practices Jared Mauch (Feb 10)
- Re: Cisco says attacks are due to operational practices Paul Ferguson (Feb 10)
- Re: Cisco says attacks are due to operational practices Chris Cappuccio (Feb 10)
- Re: Cisco says attacks are due to operational practices Paul Ferguson (Feb 10)
- Re: Cisco says attacks are due to operational practices Chris Cappuccio (Feb 10)
- Re: Cisco says attacks are due to operational practices John M. Brown (Feb 10)
- Re: Cisco says attacks are due to operational practices Bora Akyol (Feb 11)
- Re: Cisco says attacks are due to operational practices adrian (Feb 11)
- Re: Cisco says attacks are due to operational practices Adam McKenna (Feb 11)
- Re: Cisco says attacks are due to operational practices Stephen Sprunk (Feb 11)
- Re: Cisco says attacks are due to operational practices Paul Ferguson (Feb 11)
- Re: Cisco says attacks are due to operational practices Vijay Gill (Feb 10)
- Re: Cisco says attacks are due to operational practices John M. Brown (Feb 10)
- Re: Cisco says attacks are due to operational practices Wayne Bouchard (Feb 10)
- Re: Cisco says attacks are due to operational practices Richard Steenbergen (Feb 10)
- Re: Cisco says attacks are due to operational practices Marc Slemko (Feb 10)
- Re: Cisco says attacks are due to operational practices John M. Brown (Feb 10)
- Re: Cisco says attacks are due to operational practices Steve Sobol (Feb 10)