Re: sshd PORT FORWARDING / SESSION TIME ideas

From: Alvin Austin (alvin@crlogic.com)
Date: 01/16/02


From: Alvin Austin <alvin@crlogic.com>
Date: Wed, 16 Jan 2002 09:31:53 -0600


"Richard E. Silverman" wrote:

> >>>>> "AA" == Alvin Austin <alvin@crlogic.com> writes:
>
> AA> How would you do this with SSHD?
>
> Which "sshd"? OpenSSH? F-Secure? ssh.com? VanDyke's VShell? And running
> on what platform?
>

openSSH on linux...

>
> AA> 1) Port forwarding restrictions...
>
> None of these are effective if you are allowing normal shell access to
> your users, as they can simply use their own forwarding software over the
> SSH connection -- which could be as simple as:
>
> % socket -bcfslqp "ssh <server> telnet localhost 25" 2001
>
> for something equivalent to "ssh -L 2001:localhost:25 <server>".
>

The users would not have shell access. Instead of /bin/sh, they would have a
very restrictive
shell script that would count down their remaining session time in minutes, and
allow them to
change their password (which would give them access to ssh for the purposes of
port
forwarding only; no interactive access, no mail on this gateway, etc.)

>
> --
> Richard Silverman
> slade@shore.net



Relevant Pages

  • secure port forwarding without shell access
    ... I have the following set up on linux with the intention of allowing ... specific ports to be forwarded and to not allow shell access to these ... This seems to limit port forwarding and prevent shell access. ...
    (comp.security.ssh)
  • Whiteboard and application sharing do not work
    ... I am using MSN Messenger V6.2 ... (Windows Messenger is also installed) ... Port Forwarding: ... ports under Port Forwarding. ...
    (microsoft.public.windowsxp.messenger)
  • Re: Please explain port forwarding..
    ... >> So is port forwarding a security risk? ... > your MS SQL server, you would be compromised in a short time since there ... > If you need port forwarding you need to secure the machine that is the ...
    (alt.computer.security)
  • Re: Agent Forwarding Question for the list
    ... So much of the information I find is about Port Forwarding, which I know is not the same as Agent Forwarding, which is what I am asking about. ... ssh-agent is on the desktop, I put my key in with ssh-add, ssh someuser@server1 lets me in. ...
    (SSH)
  • Firewall Help with Bittorrent
    ... I'm having a hard time getting the port forwarding for the ... trying to download FC Test 1 and get slow download speeds. ... Registered Linux User #214499 http://counter.li.orgl ...
    (Fedora)