oss-sec mailing list archives
Re: Security risk of server side text editing in general and vim.tiny specifically
From: Leonid Isaev <leonid.isaev () jila colorado edu>
Date: Sat, 4 Nov 2017 23:13:29 -0600
On Fri, Nov 03, 2017 at 03:39:00PM +0100, Solar Designer wrote:
... reuse sshd(8). And this last possibility brings us to what we can (and I sometimes do) use already - setting up temporary SSH keys with forced "cat < ..." or "cat > ..." commands, and using SSH for safely exchanging files by users of the same host, or of different hosts for this matter. It's just manual setup each time, and we could want to provide convenient tools to automate that.
Ah, great :) I've been using sshd and ssh as a sudo replacement on all machines, inspired by your old article about insecurities of the latter (with locked root password, so su also doesn't work). Of course, sshd is in general listens on localhost:22. As for the keys, the keypair to access root, as well as root's authorized_keys file, are generated at each boot and stored in tmpfs. Thanks for the idea, -- Leonid Isaev
Current thread:
- Re: nvi crash recovery, (continued)
- Re: nvi crash recovery Jakub Wilk (Nov 04)
- Re: nvi crash recovery (was Re: [oss-security] Re: Security risk of server side text editing in general and vim.tiny specifically) Daniel Micay (Nov 03)
- Re: Re: Security risk of server side text editing in general and vim.tiny specifically Christos Zoulas (Nov 03)
- AW: Re: Security risk of server side text editing in general and vim.tiny specifically Fiedler Roman (Nov 06)
- Re: Security risk of server side text editing in general and vim.tiny specifically Solar Designer (Nov 13)
- AW: Security risk of server side text editing in general and vim.tiny specifically Fiedler Roman (Nov 13)
- Re: Security risk of server side text editing in general and vim.tiny specifically Fiedler Roman (Nov 03)
- Re: Security risk of server side text editing in general and vim.tiny specifically Fiedler Roman (Nov 03)
- Re: Security risk of server side text editing in general and vim.tiny specifically Solar Designer (Nov 03)
- Re: Security risk of server side text editing in general and vim.tiny specifically Solar Designer (Nov 03)
- Re: Security risk of server side text editing in general and vim.tiny specifically Leonid Isaev (Nov 05)
- Re: Security risk of server side text editing in general and vim.tiny specifically Solar Designer (Nov 03)
- Re: Security risk of server side text editing in general and vim.tiny specifically Fiedler Roman (Nov 03)