Re: SSH auto trust all host keys,how to?
- From: Chuck <skilover_nospam@xxxxxxxxxxxxxx>
- Date: Thu, 15 Jun 2006 19:24:52 GMT
Richard E. Silverman wrote:
"Chuck" == Chuck <skilover_nospam@xxxxxxxxxxxxxx> writes:
Chuck> Not all attacks come from outside your network. This idea is
Chuck> often overlooked.
Re-read:
>> ... This by itself won't help you unless the host you're trying to
>> spoof is on the same IP network as you, ....
Saw that the first time. I just wanted to emphasize a point that is
often overlooked. Most network and system admins spend 99% of their
efforts protecting against hi-tech external attacks when most successful
attacks are either low tech or internal.
Case in point is a guy I know who secured every aspect of his network
application with SSL - except for the printer used to print paychecks.
Wouldn't you know it that someone set up a packet sniffer on the
printer's subnet and was able to steal payroll info.
In another case, a company I used to work for hired a security auditor
who was able to get application passwords by very low-tech means. He
called the computer room posing as an irate executive who couldn't log
on, and someone just gave him the password over the phone. Needles to
say heads rolled (not mine).
.
- References:
- SSH auto trust all host keys,how to?
- From: SSKillZ
- Re: SSH auto trust all host keys,how to?
- From: Michael Heiming
- Re: SSH auto trust all host keys,how to?
- From: SSKillZ
- Re: SSH auto trust all host keys,how to?
- From: Chuck
- Re: SSH auto trust all host keys,how to?
- From: Chuck
- Re: SSH auto trust all host keys,how to?
- From: Richard E. Silverman
- Re: SSH auto trust all host keys,how to?
- From: Chuck
- Re: SSH auto trust all host keys,how to?
- From: Richard E. Silverman
- SSH auto trust all host keys,how to?
- Prev by Date: Re: SSH auto trust all host keys,how to?
- Next by Date: Re: How to configure dual SSH keys?
- Previous by thread: Re: SSH auto trust all host keys,how to?
- Next by thread: Re: SSH auto trust all host keys,how to?
- Index(es):
Relevant Pages
|
|