3 ms·
Its pretty trivial to disable the ability of users to listen on certain ports higher than 1024 with a firewall config.
by throwaway2048 5y ago
Its pretty trivial to disable the ability of users to listen on certain ports higher than 1024 with a firewall config.
- JimDabell 5y agoIn practice, people won’t do that. Case in point: the article doesn’t mention this mitigation at all. It introduces an additional attack vector and tells you it’s safer.
- usr1106 5y agoA firewall config can block listening? What would that firewall config be? The firewall can block packets by owner uid. But I am not sure who is the owner in legitimate sshd case. Root or the user logged in? SELinux can do it, probably other LSMs, too.
- throwaway2048 5y agoyou cant block the actual port bind, but you can block any packets from reaching it, so the difference is mostly semantics
- usr1106 5y agoYes, but that port needs to remain "open" for the legitimate sshd traffic. Can you see a difference in ownership as the firewall sees it between sshd and some user daemon? Sshd drops root partially when login succeeds.
- throwaway2048 5y agothat has nothing to do with sshd's listening socket, which remains owned by root
- usr1106 5y agoSure the listening one remains owned by root. But the connected one? If you limit packets from/to e.g. 2222 to uid 0, will legitimate ssh traffic work? I don't say it won't, genuinely unsure. Haven't tried and today is a holiday. Maybe tomorrow :)