Re: Newbie - is this connection secure

From: Jacob Nevins (jacobn_at_chiark.greenend.org.uk)
Date: 12/01/04


Date: 01 Dec 2004 00:10:53 +0000 (GMT)

Two Heads <twoheads@NOSPAMtiscali.co.uk> writes:
>my ISP help desk tell me that we only have SSH connections for
>root, not to designated client folders.

The log you give certainly looks as though you can successfully connect
with SSH, authenticate yourself, and start up SFTP. (I'm not familiar
with WinSCP; this assumes that the messages generated from PuTTY-derived
code have their usual meanings; but it seems pretty unlikely that you'd
get the messages you do unless WinSCP were actively lying to you, which
seems unlikely.)

Perhaps they mean _shell_ access is only for root? It's possible to have
SFTP access (over SSH) without having shell access over SSH.



Relevant Pages

  • RE: Linux hacked
    ... Also, what exactly did the history file show, can you paste it into a mail ... > First let me say I'm a security novice. ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
    (Security-Basics)
  • Re: Linux hacked
    ... To find out what kernel version you are running, type "uname -a" without ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
    (Security-Basics)
  • Re: X11Forwarding, ssh -X, and /bin/su
    ... ]>but I'm not really tunneled using ssh then, ... ]connecting to the X server and have the home directory NFS-mounted ... ](unless you leave root unmapped over NFS, ... ]root-readable place and set the environment $XAUTHORITY variable ...
    (comp.security.ssh)
  • RE: Linux hacked
    ... hack the box, pull the drive and save it. ... Use the newest versions of Gentoo, Apache, SSH, PHP and Squirl Mail. ... been unsuccessful in getting root back. ... I found a hidden directory /var/tmp/.tmp that has a bunch of directories ...
    (Security-Basics)
  • RE: Linux hacked
    ... Was any of the sites running a php nuke or another portal or system that is vuln ... been able to use that with a locla root exploit to gain root on the machine. ... > hack the box, pull the drive and save it. ... > Use the newest versions of Gentoo, Apache, SSH, PHP and Squirl Mail. ...
    (Security-Basics)