port fwd as user not root?

From: Mathias Koerber (mathias@koerber.org)
Date: 05/24/02


From: Mathias Koerber <mathias@koerber.org>
Date: Fri, 24 May 2002 10:30:31 +0800

When using OpenSSH 3.0 as server (and SecureCRT as client), I find
that the port-forwards (local) I make to my server are opened on the
server by the sshd which at that point is still root.

As an example, I define
        LOCAL:12345 otherhost:25

On the server system, I see the following processes:

root 125 S May05 10:12 /usr/local/sbin/sshd
root 21288 S 10:01 0:04 \_ /usr/local/sbin/sshd
mathias 21289 SW 10:01 0:00 \_ [bash]
mathias 21297 S 10:01 0:00 \_ ssh-agent /usr/bin/bash

netstat shows the connection:
tcp 0 0 myserver:47552 otherhost:25 ESTABLISHED

lsof shows the owner of the port to be root:
$ lsof -i TCP:47552
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
sshd 21288 root 9u inet 627601 TCP
myserver:47552->otherhost:smtp (ESTABLISHED)

Is there any way I can make this instance of sshd assume my identity
(mathias) instead of hanging around as root?

The problem I'm facing is that identd reports the owner of the
connection as root, while I would like it to show the userid I
logged in as..

Mathias



Relevant Pages

  • RFX Networks/ RackAdmin.com ALERT
    ... below was posted to some security websites. ... | in security and scalable server management on varying levels. ... Got Root? ... Your Server login ID is: ...
    (comp.os.linux)
  • RFX NETWORKS ALERT
    ... below was posted to some security websites. ... | in security and scalable server management on varying levels. ... Got Root? ... Your Server login ID is: ...
    (alt.linux)
  • Solaris Sparc 9 12/3 Core ./installer failing due Java?
    ... system SUNWadmr System & Network Administration Root ... system SUNWapchd Apache Web Server Documentation ... system SUNWapchu Apache Web Server (usr) ... system SUNWaudd Audio Drivers ...
    (comp.unix.solaris)
  • core install of Solaris 9 (sparc) package list can be trimmed ?
    ... This is a server that will have very specific reasons ... system SUNWadmr System & Network Administration Root ... system SUNWeu8os American English/UTF-8 L10N For OS Environment User Files ... system R SUNWfcip Sun FCIP IP/ARP over FibreChannel Device Driver ...
    (comp.unix.solaris)
  • [Full-Disclosure] RFX Networks
    ... | in security and scalable server management on varying levels. ... | monitor to take action during situations of service failure. ... Got Root? ... Your Server login ID is: ...
    (Full-Disclosure)