4 ms·
I'm surprised nobody noticed this bug at Apple before the release. Is there nobody there that connects by hostname to a ssh server with a port > 8192?
by dimtion 7y ago
I'm surprised nobody noticed this bug at Apple before the release. Is there nobody there that connects by hostname to a ssh server with a port > 8192?
- deleted 7y ago[deleted]
- saagarjha 7y agoProbably not. I doubt I’ve used a port that high.
- Yetanfou 7y agoWhy not? I regularly use 5-digit ports - 3-digit prefix plus 2-digit 'official' port - for various systems which reside behind a NATting router.
- the_mitsuhiko 7y agoI'm pretty sure it's generally not advisable to use ports this high since they are used for other purposes.
- Avamander 7y agoAll purposes are equally as valid on unallocated port ranges. Inconfigurable port ranges with no fallback when those ports are in use is bad design.
- user5994461 7y agoHigh port numbers, above 30000 usually, are ephemeral ports and get pre-empted by the system. They're not safe to listen to for server applications.
- syncsynchalt 7y agoPorts <1024 require root access to bind, so on a multi-user system it would be insecure to run ssh on such a high port. (Granted, multi-user hosts are very rare nowadays).
- codegladiator 7y agoIsn't 8080 used almost everywhere ?
- rimliu 7y ago8080 < 8192
- desdiv 7y ago8080 is less than 8192. This bug only happens when the port is _higher_ than 8192.
- codegladiator 7y agosorry my bad what was i thinking
- Yeri 7y agoNot for SSH. Common alternate SSH ports are 222 or 2222 which are well below.
- SteveNuts 7y agoFor webservers sometimes, never seen that used for ssh.
- bni 7y ago443 to pass the stupid corporate firewall. I used that once 15 years ago anyway.
- saagarjha 7y ago< 8192, and that’s mostly the alternate HTTP port.
- floatingatoll 7y agoI haven't in ten or twenty years, no.
- gray_-_wolf 7y ago> Is there nobody there that connects by hostname to a ssh server with a port > 8192? I use alternative port but < 1023 since binding to those ports requires root. And I've never seen it being used. I'm not saying it's not, just that I did not see it in 10 years. So it probably really is not that common.
- pwg 7y agoI'm not. Not all 'testers' actually try to test edge cases. The /good/ testers do try edge cases, but for every /good/ tester you have, you'll have hired 100+ testers who do little more than check that the standard happy-path works correctly and sign off as "passes tests". The good testers all tend to fall into what Bruce Schneier calls the 'Security Mindset' way of thinking: https://www.schneier.com/blog/archives/2008/03/the_security_mi_1.html https://www.schneier.com/blog/archives/2008/03/the_security_...
- Hamuko 7y ago>Not all 'testers' actually try to test edge cases. Yeah, but surely macOS devs are eating their own dog food.
- bangonkeyboard 7y ago"I've learned that Apple engineers have internal tools which allow them to delete macl xattr as well as to bypass other Catalina privacy and sandbox protections without rebooting and disabling SIP. "Inside Apple they don't suffer the same problems as external users and developers." — https://twitter.com/lapcatsoftware/status/1219292758910828544 https://twitter.com/lapcatsoftware/status/121929275891082854...
- sigzero 7y agoAnd a simple shell script to test it would be easy.
- amelius 7y agoWell, I hope for them they put it in their automated regression test suite now.