oss-sec mailing list archives
lxc-sshd security issues?
From: "Michael K. Johnson" <johnsonm () rpath com>
Date: Wed, 4 Mar 2009 17:30:33 -0500
I have not received any response to this query upstream, and I was wondering if anyone else has noticed this issue, and if so, if they have any plans with regard to it. rPath isn't shipping lxc at this point, so we have no plans for a security advisory. But does pre-configured account information including root and user passwords bother anyone else here? ----- Forwarded message from "Michael K. Johnson" <johnsonm () rpath com> ----- Date: Thu, 12 Feb 2009 14:49:45 -0500 From: "Michael K. Johnson" <johnsonm () rpath com> To: legoater () free fr Subject: lxc-sshd security issues? I'm guessing, from the contents of the tarball in lxc-sshd, that you might be responsible for building lxc-sshd. I noticed three potential security issues while briefly perusing lxc-sshd: o Pre-packaged host keys instead of generating unique host keys within the script or optionally copying the host keys from the system on which you are running lxc-sshd o Pre-packaged root password instead of setting it in the script o Pre-packaged legoater password ditto Obviously, the pre-packaged passwords are a potential security risk for you if you are using those passwords anywhere, and could also be considered to be "back doors" if they actually enable any access by default. I haven't tested any of that -- it just seemed odd while inspecting the tarball contents. In addition, I noticed /root/.bash_history was packaged in the tarball, which I am guessing was not intended. ----- End forwarded message -----
Current thread:
- lxc-sshd security issues? Michael K. Johnson (Mar 04)
- Re: lxc-sshd security issues? Michael K. Johnson (Mar 05)
- Re: lxc-sshd security issues? Steven M. Christey (Mar 17)
- Re: lxc-sshd security issues? Michael K. Johnson (Mar 18)
- Re: lxc-sshd security issues? Steven M. Christey (Mar 17)
- Re: lxc-sshd security issues? Michael K. Johnson (Mar 05)