Expect Scripts and Security Issues

From: Jeff Friedman (jfriedman_at_ndwcorp.com)
Date: 05/22/03

  • Next message: Jacques Bourdeau: "Hardening an old Ultrix server"
    Date: 22 May 2003 10:08:06 -0700
    
    

    Hello,

    We are planning on implementing 'Expect Scripts' on a few Unix / Cisco
    devices. These will log into the servers using SSH, then record a few
    basic system functions.

    I was wondering what the security and vulnerability concerns might be?
    The FAQ's on the Expect site do not contain any security issues.

    Thank you,

    Jeff Friedman
    jfriedman@ndwcorp.com


  • Next message: Jacques Bourdeau: "Hardening an old Ultrix server"

    Relevant Pages

    • dmz security policy - ssh through jump server
      ... changes to how people/processes access servers within the DMZ. ... From there you could then ssh wherever you need to ... to setup the ssh tunnels or a set of scripts run by the same user step ... Back to the original point of this post, what is the added security to ...
      (comp.security.firewalls)
    • Re: [SLE] Tightening default SUSE Linux security
      ... I would like to discuss possibilities to improve default SUSE Linux security. ... Talking about servers, sitting in server farm with controlled physical ... add a non root user and disable ssh login as root. ... your servers (for instance for mysql it would mean disabling remote ...
      (SuSE)
    • Re: Reverse SSH tunelling
      ... > servers will be in private network space behind firewalls. ... > tunnel open so that I can access that console, ... Security os pf the utmost concern, ... > some sort of encrypted tunnel, hence the thought of ssh, but I don't ...
      (Focus-Linux)
    • Re: Expect Scripts and Security Issues
      ... These will log into the servers using SSH, ... > basic system functions. ... > The FAQ's on the Expect site do not contain any security issues. ... Secure, reliable hosting you expect and deserve! ...
      (comp.security.unix)
    • Re: [Full-disclosure] Why Vulnerability Databases cant do everything
      ... best to relegate programming to a ... is a big difference between these two views of information security. ... but not nearly as important as designing secure systems. ... My favorite example to illustrate this point - ssh. ...
      (Bugtraq)