Re: Public key authentication troubles

From: Mike Delaney (mdelan_at_computer.org)
Date: 05/27/04


Date: Wed, 26 May 2004 18:49:01 -0500

On Thu, 27 May 2004 00:46:09 +0200 in <c936cd$1m3$1@news-reader1.wanadoo.fr>,
Nicolas Bertolotti said something similar to:
: Yes, but then, the owner of the .ssh folder and the .ssh/authorized_keys
: file would not be "victim" anymore and, as far as I remember, sshd wouldn't
: accept the key in this case.

Some systems (e.g. Solaris with rstchown = 0 set in /etc/system) allow
non-root users to chown files (as bad an idea as that is), so simply
testing the ownership of the authorized_keys file is insufficent.



Relevant Pages

  • Re: Public key authentication troubles
    ... Yes, but then, the owner of the .ssh folder and the .ssh/authorized_keys ... file would not be "victim" anymore and, as far as I remember, sshd wouldn't ...
    (comp.security.ssh)
  • Re: Another sensless shooting.
    ... >> Another terrible loss to society. ... >>>Police said the victim, apparently a disgruntled employee at the company, ... >>>victim threatened he would show up with a gun. ... The owner said the victim ...
    (alt.politics)
  • Another sensless shooting.
    ... >DALLAS -- Police are investigating a shooting death at a Christmas lights ... >victim threatened he would show up with a gun. ... The owner said the victim ... >"We had a disgruntled employee that came back this morning. ...
    (alt.politics)
  • Kudos: PalmPilot(5) email working again
    ... No real reason to, as a Palm Five owner, it's an ... orphan, and almost nothing runs on it anymore. ...
    (Fedora)
  • Re: New House Alarm - Am I locked out?
    ... T%hey ripped off the prior owner. ... just another victim of their scam. ... the alarm company in question is ... Sarasota · Florida · 34233 ...
    (alt.security.alarms)