3 ms·
So instead of exposing thoroughly tested OpenSSH to the web, I’m exposing this thing, which can also run shell commands…
by hello_computer 2y ago
So instead of exposing thoroughly tested OpenSSH to the web, I’m exposing this thing, which can also run shell commands…
- fn-mote 2y agoThere are many points made in the presentation, including that a significant number of ~~targets~~ hosts are not running OpenSSH. See the list and the claims that some classes of them are important. The swipe at "running shell commands" isn't very credible, but the second attack surface is legitimate.
- hello_computer 2y ago4th bullet from the bottom sounds credible to me: > Supports the execution of shell commands on behalf of valid SPA packets. Even if it were only a statically configured command (no idea if it is or isn't), as soon as that door is opened, it leads to a morass.
- exabrial 2y agoJust had a random thought… what about port knocking, but the combination was TOTP’d? Port knocking is visible to third parties… but if the combination was a TOTP nonce, guessing the correct combination would be fairly difficult.
- hello_computer 2y agoDidn’t have a beef with the general idea or the cryptography (assuming that some form of replay protection was already baked-in) so much as the idea that exposing a novel, less-tested, non-trivial service is a security win. If the implementation (TOTP or not) were dead-simple, I think SPA would be a win, but as soon as we get to dynamic cross-platform firewall-fiddling and custom commands, we are no longer in “dead-simple” territory.
- deleted 2y ago[deleted]