Re: Expect Scripts and Security Issues

From: 2Host.com - Robert (admin_at_-NOSPAM-2host.com)
Date: 05/24/03


Date: Fri, 23 May 2003 16:04:34 -0700

Jeff Friedman wrote:
>
> Hello,
>
> We are planning on implementing 'Expect Scripts' on a few Unix / Cisco
> devices. These will log into the servers using SSH, then record a few
> basic system functions.
>
> I was wondering what the security and vulnerability concerns might be?
> The FAQ's on the Expect site do not contain any security issues.

It's a matter of how you store the information to connect. Will you pass
the password for login in a script or file, or will use you keys? Both
are insecure for various reasons. Personally, and this is maybe overkill
for some people, I'd just create an interface to communicate over the
network to perform only the tasks I want to have performed on the other
servers via a client-server method, which can be far more secure and
controlled. It's not really that much work involved.

-- 
Regards,
Robert McGregor - Email: admin@(remove)2host.com. Phone: 530-941-0690
Server admin, support, programming for shared & dedicated web servers
Secure, reliable hosting you expect and deserve! http://www.2host.com


Relevant Pages

  • Re: [fw-wiz] I wonder, how to test..
    ... >responsible for security at our company, ... >of my head make me wonder how secure it all is. ... Internally locking down the servers: ... administrator's privileges if he managed to execute code with webserver ...
    (Firewall-Wizards)
  • Re: Anyone hear of ANSA (Asp.Net Security Analyser)??
    ... you if your servers that provide Asp.Net shared hosting ... ANSA (Asp.Net Security Analyser) is not a commercial ... results will tell us if your servers are secure or not. ...
    (comp.security.misc)
  • Re: How secure is software X?
    ... in my opinion a software can either be secure or not secure. ... to classify security like that would be to condemn every ... How in-depth a fuzzing to we apply for this standard? ... For example, SMTP servers have a pretty standard interface, ...
    (Bugtraq)
  • Re: How to access I/O port directly in VC6.0?
    ... several multinationals, worked with the research division in one case, and ... Their "security" as far as servers was a joke; ... servers, which WERE secure, including VPN access, but the corporate ...
    (microsoft.public.vc.mfc)
  • Ensuring that a sever and website are secure
    ... we would like to be as sure as possible that the servers and data on ... them are secure before we launch this service. ... Several people have recommended having a security audit done once our ... technical staff believe the website and servers are secure. ...
    (comp.security.misc)