3 ms·
This is a neat hack, but beyond that, I'm not sure what the practical usage is. If '.authorized_keys` can be modified by the user, then one-time access is easi
by bascule 11y ago
This is a neat hack, but beyond that, I'm not sure what the practical usage is.
If '.authorized_keys` can be modified by the user, then one-time access is easily escalated to many-time access.
If not, they can still leave a process running on the host to obtain access later. After all, you're giving them remote code execution.
You could try to prevent them from obtaining shell access and use SSH as an encrypted transport and AuthN system. That's not really discussed in the post at all.
This post is really more like "Look ma, .authorized_keys can run commands!"
- gkop 11y ago> After all, you're giving them remote code execution. I may be wrong, but I believe ssh can be hardened more or less effectively against RCE, and still be of practical use (eg. for file uploads). Edit: which you sort of say in your own comment - you and I can both imagine interesting uses :)