21 ms·
How would this be deployed? If you already have access to the users authorized-keys it seems like you'd have enough access to do many other, more damaging thing
by kayson 3y ago
How would this be deployed? If you already have access to the users authorized-keys it seems like you'd have enough access to do many other, more damaging things.
- cozzyd 3y agoWell, for example GitHub supports ssh keys for login. I assume it's not vulnerable to this, but I don't know...
- Operyl 3y agoSpoiler: It isn't, it doesn't even run OpenSSH at this point anyway[1]. Gitlab has gitlab-sshd[2], which can be used in place of the OpenSSH-based approach as well. It is used on gitlab.com. [1]: debug1: Remote protocol version 2.0, remote software version babeld-51390fc7 [2]: https://docs.gitlab.com/ee/administration/operations/gitlab_sshd.html https://docs.gitlab.com/ee/administration/operations/gitlab_...