4 ms·
If the password used for the user, in the remote machine, is different from that of the machine he/she is connecting from, the attacker will not be able to gain
by pecg 9y ago
If the password used for the user, in the remote machine, is different from that of the machine he/she is connecting from, the attacker will not be able to gain root access, even if the account has permission to escalate priviledges.
- inetknght 9y agoI don't see how the authentication used for a user on a local machine has anything to do with the authentication of a user on a remote machine unless both are using the same domain authentication (RADIUS, Active Directory, etc). Even then, there can be cache involved.
- closeparen 9y agoThere could be a local compromise that exposes the SSH keys (for login) but not the remote password (for sudo).
- inetknght 9y agoMy parent comment indicates that the password needs to be different. Your comment does not support that. First, sudo should not be cached for this very reason. Second, agent caching should never be enabled for this very reason. Third, agent forwarding should never be enabled for this very reason. Indeed, using key authentication to log in and then using a password to upgrade to sudo is, I think, very reasonable.
- merb 9y ago> Indeed, using key authentication to log in and then using a password to upgrade to sudo is, I think, very reasonable. which most often is not the default on vps/root/clouds, that's basically my point. if you use sudo, use it with a password.
- deleted 9y ago[deleted]
- geofft 9y agoThe attacker can still do things like - attach to an existing screen session that has an existing process under sudo inside it - edit .bashrc to alias sudo to something that records the password, then come back later - spawn a background process that waits for the user to run sudo, then opens the pty and uses TIOCSTI to type commands at it Also, if the attacker actually has control over the sysadmin's local machine, they can do a lot more damage, like any of the above locally, or - send an email from the admin's account to the team saying "Hi, I'm trying to run this command but I left my RSA token at home, can anyone help?" - add a browser extension that rewrites all <pre> tags to include a https://thejh.net/misc/website-terminal-copy-paste https://thejh.net/misc/website-terminal-copy-paste -style attack - commit to code or configuration-management repos adding a back door and trigger a deployment None of these are technically difficult attacks. Requiring a separate sudo password might slow down a script kiddie, but that's about it.
- 616c 9y agoThanks, kind stranger. You taught even me some I didn't know!