4 ms·
For me on Windows it just prompts to open WinSCP, which registered itself under `HKEY_CLASSES_ROOT\ssh`, the same as Chrome does for any other unknown protocol.
by mubou 2y ago
For me on Windows it just prompts to open WinSCP, which registered itself under `HKEY_CLASSES_ROOT\ssh`, the same as Chrome does for any other unknown protocol.
- ggm 2y agoprobably could tune it to an ssh app, if I had one. Terminal running ssh is fine by me!
- keepamovin 2y agoFor me sadf://asdfsad Goes to google search on Chrome, and Safari just refuses. There might be some way this leaks ssh public key information (it's a normal ssh session afterall) - but you have to hit OK on the intent modal. My bet is there could be a vuln in the URL parsing of these scheme links. It's probably not so simple, but it screams: "Shell injection" when you can have a protocol link that ends up opening up a CLI app. But to be clear, I am in no way against the protocol links caps of browsers, especially SSH, I think it's super useful. Most likely all such bugs would be found by now - but maybe something more complex, some specially crafted SSH url on some systems might be able to trigger something unintended (pun intented haha :))