ssh-3.2.2 + X11 forwarding +tcpwrapper

From: Eric Vielet (Eric.Vielet@crihan.fr)
Date: 01/28/03


From: "Eric Vielet" <Eric.Vielet@crihan.fr>
Date: Tue, 28 Jan 2003 11:18:08 +0100

Hi all,

I installed ssh-3.2.2 on a machine called jack (aix-5.1), on something
seems a little bit strange to me :
Everythings OK. I compiled with "--with-libwrap --without-ipv6"

I authorized a machine called spectrum to ssh to jack, and to launch a X
tool :
hosts.allow on jack :

sshd: spectrum
sshdfwd-X11: spectrum

Is it right ?

When i ssh from spectrum to jack, i get a shell on jack -> ok
But when i try to lauch an x tool (xterm for example), it was denied by
the wrapper.
I debug all i can, and saw that the denied was from jack ???

I modify my hosts.allow on jack :
sshd: spectrum
sshdfwd-X11: jack

=> now, all works fine, and i can lauch my xterm.

Q: i don't understand why i have to put jack, and only jack, in my
hosts.allow, rather than hosts from which i ssh ?? Because it meens that
all hosts that ssh on jack can lauch X applications ?
Is there something wrong in what i've done ?

Regards

PS: i tried on another host, under Redhat-8.0, and had the same problem
...



Relevant Pages

  • Re: how to start iptables on dsl ppp0
    ... packets just before they get dropped by the chain policy. ... for example one to accept ssh. ... to use the "-I" option so that packets matching this rule would not ... Greetings, Jack. ...
    (comp.os.linux.security)
  • Re: [SLE] cups admin help
    ... On 7/8/05, Jack Malone wrote: ... I had it setup in past before I redid the server. ... ## maybe local network as well.. ... You should additionaly restrict the access to some hosts or network.. ...
    (SuSE)
  • Re: Restrict number of users sharing 1 user
    ... The way I would do this, is with ssh. ... For non ssh, you can create a unique group for each of your 3 or 4 users, ... and set the generic user to allow su from those groups only There is no way ... How is it possible to know that jack did it?? ...
    (comp.unix.aix)
  • sudo over ssh
    ... If I run sudo over ssh: ... I will be prompted for my ssh passphrase and then my password on ... -Random Jack ...
    (comp.unix.admin)