3 ms·
> Step one is getting you to use a compromised server. This is not at all uncommon. Consider I need to send you files, either once or on a batch schedule. Yo
by eof 8y ago
> Step one is getting you to use a compromised server.
This is not at all uncommon. Consider I need to send you files, either once or on a batch schedule.
You say, "give me your key, you can drop them on this server"
I feel safe since I am just writing files to your server, not expecting you are going to drop arbitrary code that will run next time I open my terminal.
- jedberg 8y agoUnless I’m mistaken you’d still be safe. The vuln would only work if you were pulling files from an untrusted host, not pushing to it. But if I wanted to share files with you, I’d just put them on the web, unless we already have a relationship where you can ssh somewhere that I have access to. In which case I assume we’re trusted or you’ve at least verified the host key.
- ATsch 8y agoWell, it's basically a privilege escalation vulnerability. If you've owned some server, you now have a possibility to get access to the admins local machine too, likely giving you admin access to the whole infrastructure. If you "trust" any of these things is irrelevant, as that trust might be misplaced and the security model should keep you safe with compromised servers regardless.
- Cpoll 8y agoIt's the reverse, but it's almost the same. "Give me your key, and then take these files from my server." I feel safe, because I think I'm going to cat a text file, not execute it.