4 ms·
I just tested it and i didn't get it to work. ~/.ssh/rc is not executed directly but given as an parameter to your shell (/bin/false) which will ignore the para
by mrud 15y ago
I just tested it and i didn't get it to work. ~/.ssh/rc is not executed directly but given as an parameter to your shell (/bin/false) which will ignore the parameter.
To be more precise sh -c /bin/false -c '/bin/sh .ssh/rc' is executed where /bin/false is your shell as ssh uses popen(3) to run the command /bin/false -c '/bin/sh .ssh/rc'. I tested several shells which may be used as sh and none seems to read a user configurable file.
If you use a static linked shell and enabled PermitUserEnvironment an attacker can still use LD_* variables to circumvent restrictions as /bin/sh is typically dynamically linked.