3 ms·
Ive used something like ''' ssh -t user@host /bin/sh ''' To bypass shell restrictions in the past, but I'm not sure if that will work with your example.
by batch12 3y ago
Ive used something like
'''
ssh -t user@host /bin/sh
'''
To bypass shell restrictions in the past, but I'm not sure if that will work with your example.
- blueflow 3y agoThis won't work because the command send to the server is not an argument vector, but a command string interpreted by the users login shell. `ssh -t user@remote /bin/sh asdf` would execute `/bin/false -c "/bin/sh asdf"` on the remote.
- batch12 3y agoMakes sense, thanks for the clarification.
- LinuxBender 3y agoFeel free to try it out sftp share@ohblog.net (no pw) # grep share /etc/passwd /etc/shadow /etc/passwd:share:x:5002:5000::/data/sftp/share:/bin/false /etc/shadow:share::19614:::::: The partially redacted /etc/ssh/sshd_config is copied to /pub/ in the SFTP account. If you can bypass the restriction please do share how it was done. I don't offer bug bounties but I think people would find it interesting. OS is Alpine Linux. All CPU mitigations are disabled in the VM. No MAC As in no SElinux or AppArmor. I won't complain, just pretty please don't DDoS the server or anything that would make that VPS do work. Feel free to also tinker with the web and voice chat server on that node.