5 ms·
Gentle reminder: when sshing into unknown places remember to check your forwarding and dont use your github/etc username.
by throwaway47292 5y ago
Gentle reminder: when sshing into unknown places remember to check your forwarding and dont use your github/etc username.
- pheasantquiff 5y agoSage advice. This is really more suited to IRC but ssh is something everyone has readily available. It has a much lower barried to entry. Isn't a specific effort required to have [port] forwarding? I don't think anyone will do it accidentally, even were I nefarious. In other words, if you don't know what "forwarding" is, then you don't have to worry.
- throwaway47292 5y agonono ssh is great medium, just most people have agent forwarding by default, and its annoying that it can be exploited by malicious ssh host[1] [1]: https://book.hacktricks.xyz/linux-unix/privilege-escalation/ssh-forward-agent-exploitation https://book.hacktricks.xyz/linux-unix/privilege-escalation/...
- binwiederhier 5y agoThat's a great resource. I had never heard of this attack vector before. Thanks for sharing the link.
- tyingq 5y agoThis: "ssh -o ClearAllForwardings=yes ..." seems like it would be a good catch-all.
- SavantIdiot 5y agoCan I stick that into ~/.ssh/config somehow so it is always a default, or should i just alias it?
- thaumasiotes 5y agoIf you're going to change your config, couldn't you just... not have forwarding?
- est 5y agoAlternatively you can config id_rsa from different path specifically for github and your work repo. Use a general non-identifiable id_rsa to play with public ssh servers.
- Groxx 5y agoForwarding is not the default behavior, so normally you're fine. For others, if you do this: Host * ForwardAgent yes you can take this as a reminder that `Host *` is playing with fire, and just asking for accidents like this. Be extremely careful with `Host *` configs, especially with anything security-sensitive. "Careful", as in "do not do it if there's literally any risk". And if you don't know for sure, consider it a risk by default. `Host *.internal` at a minimum, or whatever hostname / dns patterns are used around you, is dramatically safer and just as convenient.
- GekkePrutser 5y agoAdditionally, setting up an SSH agent that requires confirmation for every use is a great measure to prevent abuse when you do forward it by mistake.
- digitalsushi 5y agoStronger reminder: Don't play with SSH toys using your work computer, ever, as a sensible way to remain employed
- tyingq 5y agoOne workaround...launch a Google cloud shell from a personal google account and try the ssh toy from there. It's free. https://cloud.google.com/shell https://cloud.google.com/shell
- chillingeffect 5y agoi miss the much-maligned telnet :( perfect for uncritical fun stuff like this.
- GekkePrutser 5y agoI wish I was able to SSH from work at all :)
- herdrick 5y agoWhy not use your github/etc username?
- est 5y agoit can be used to dox you
- phonethrowaway 5y agoshell escapes are real attack vector too...