Re: SSH Tunneling without console login

From: Richard E. Silverman (res_at_qoxp.net)
Date: 11/25/05

  • Next message: Witold Rugowski: "Logging port forwarding"
    Date: 24 Nov 2005 19:21:25 -0500
    
    

    >>>>> "Jesse" == Jesse <"do not spam"> writes:

        Jesse> I'm looking for an option on the SSH-Tunnel-server (PC2) side,
        Jesse> not on the SSH-Tunnel-client side (PC1). This because PC1 is
        Jesse> not fully under my control, but PC2 is.

        Jesse> Is there also an option like -N for SSHD somehow? I could not
        Jesse> find such.

    So you want to have the server allow tunneling-related channels in the
    connection protocol, but deny shell and exec channels? OpenSSH does not
    have this level of granularity, though some SSH servers do (e.g. VShell by
    VanDyke). I think the best you can do is prevent *useful* shell/command
    channels by either making the shell a restrictive program, or enforcing a
    useless remote command (e.g. /bin/false) using the command= option in
    authorized_keys (assuming you allow only publickey authentication).

    Note that you may not want to make the shell completely useless (e.g. also
    /bin/false), since sshd uses the shell for all programs run on the
    client's behalf, e.g. xauth in support of X forwarding.

    -- 
      Richard Silverman
      res@qoxp.net
    

  • Next message: Witold Rugowski: "Logging port forwarding"

    Relevant Pages

    • Re: Streaming TV channels over network
      ... channels on any of them at any given time. ... server to facilitate some resource issues. ... Can I configure the Windows Media Stream service so that it will buffer ... and use windows media encoder to encode the video ...
      (microsoft.public.windowsmedia.server)
    • Re: Does anyone make a Media Center Extender anymore?
      ... The server has to have enough tuner cards for ... three (four if you want to watch at the server). ... that XBox 360 is the tool to do that? ... cared to (kids watching different channels). ...
      (microsoft.public.windows.mediacenter)
    • Re: Callbacks to remoced clients thru firewall
      ... Genuinne Channels are not expensive at all also. ... >> Since port number is picked by the system, I have no control of which port ... My problem is that our server will soon be placed ... I can't hardcode the port number into the client. ...
      (microsoft.public.dotnet.framework.remoting)
    • Binary of HTTP config issues
      ... Server Web.config: ... Windows Client: ... hannelSinkStack sinkStack, IMessage requestMsg, ITransportHeaders ...
      (microsoft.public.dotnet.framework.remoting)
    • Re: NT Backup and Restore
      ... >It was the intelligent community I was soliciting a response from anyway. ... I have a recommendation of my own. ... I bet you troll these channels ...
      (microsoft.public.windows.server.general)