.:: Bots United ::.  
filebase forums discord server github wiki web
cubebot epodbot fritzbot gravebot grogbot hpbbot ivpbot jkbotti joebot
meanmod podbotmm racc rcbot realbot sandbot shrikebot soulfathermaps yapb

Go Back   .:: Bots United ::. > YappA > The Agora
The Agora This is the place to go if you have suggestions, or if you want to participate in Council discussions. Everyone is welcome!

Reply
 
Thread Tools
Re: Bots United start a Sourceforge project?
Old
  (#21)
Onno Kreuzinger
aka: memed / Server Admin
 
Onno Kreuzinger's Avatar
 
Status: Offline
Posts: 705
Join Date: Jan 2004
Location: germany
Default Re: Bots United start a Sourceforge project? - 31-03-2004

i know you wont get a login shell, we tried to use scp instead of ftp on this server and it failed because the login shell for ftp accounts is /bin/false.
this does work as expected, i should have said "allow login, but choose shell to be /bin/false".

i'd rather have ftp open that allow ppl. to exec /bin/bash

PMB and me tried our "best" to break into the servers root account, but both failed, the ftp exploits as well as the local shell exploits, so as of feb 2004 i consider this server to be safe, realy safe


sunny morning view from my balcony:

see our WIKI!
see our filebase!
  
Reply With Quote
Re: Bots United start a Sourceforge project?
Old
  (#22)
Terran
Member
 
Terran's Avatar
 
Status: Offline
Posts: 431
Join Date: Jan 2004
Default Re: Bots United start a Sourceforge project? - 31-03-2004

If you set the users shell to /bin/false you will not be able to use portforwarding as the connection is terminated immediately after login.

I still don't get how you want to make sure that the ssh service can only be used for this special purpose. It's simply not designed for this kind of application. You will always need some tools which will do the trick.

What might be possible is giving the user a special restricted shell (e.g. rbash) which only allows the execution of some definable programs (in this case the cvs tools). But I havn't tested this for the use with cvs, maybe it's restrictions are to restrictive as e.g. cd is not allowed.

One thing I've learned in the last 11 years as system administrator:
The only secure system is one without any connections - including the power line.
  
Reply With Quote
Re: Bots United start a Sourceforge project?
Old
  (#23)
Onno Kreuzinger
aka: memed / Server Admin
 
Onno Kreuzinger's Avatar
 
Status: Offline
Posts: 705
Join Date: Jan 2004
Location: germany
Default Re: Bots United start a Sourceforge project? - 31-03-2004

nope, ssh2 has exactly those features build in, restriction to certain programs to be executed (and only those), or restriction to not login (login=request pty) but only do portforwarding.

i will do so and give you a test login


sunny morning view from my balcony:

see our WIKI!
see our filebase!
  
Reply With Quote
Re: Bots United start a Sourceforge project?
Old
  (#24)
Terran
Member
 
Terran's Avatar
 
Status: Offline
Posts: 431
Join Date: Jan 2004
Default Re: Bots United start a Sourceforge project? - 31-03-2004

Ok, I'm looking forward how you solve those topics .
  
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump



Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
vBulletin Skin developed by: vBStyles.com