Re: scp (4.3p2) no longer allows a space in the userid.



On 2006-02-23, MeeAGhost@xxxxxxxxx <MeeAGhost@xxxxxxxxx> wrote:
As a quick fix in I had commented out the check for white space in the
okname function but before I made the change across my entire
environment I wanted a sanity check. You proved me sane. Do you think
the patch will make in the next release of openssh or will I have to
apply it to furture versions?

Looking at it, the patch isn't right. It allows spaces in the usernames
for remote-to-remote copies, which it shouldn't.

I've opened a bug and attached a better patch:
http://bugzilla.mindrot.org/show_bug.cgi?id=1164

Testing would be appreciated.

--
Darren Tucker (dtucker at zip.com.au)
GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69
Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.
.



Relevant Pages

  • Re: Error on Relinat Unix - no controlling terminal
    ... >could not set controlling tty: ... Mailing list thread, including patch: ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • Re: pam_sm_close_session doesnt run without privilege seperation
    ... > root) at session start and it mounts the directory I want. ... I have opened a bug: ... Could you please try the patch and let me know if it resolves the ... Good judgement comes with experience. ...
    (SSH)
  • Re: OpenSSH 3.7.1p1 & PAM authentication on Solaris 8
    ... it does not fix the problem. ... I had to disable the zlib version check. ... I just double checked and there isn't actually a patch, ... Good judgement comes with experience. ...
    (comp.security.ssh)
  • Re: Solution for botnets
    ... >> As others have pointed out, who is to judge what is good for others? ... > And who are you to judge that a patch worm is wrong? ... It is a judgement whether to apply it. ... infringement of the rights of others to control their own ...
    (comp.security.unix)
  • Re: login retries
    ... > Perhaps this is an easy question, but I was googling for a time and I ... The patch adds a MaxAuthTries config option. ... Good judgement comes with experience. ...
    (SSH)