4 ms·
From the ssh man page: Agent forwarding should be enabled with caution. Users with the ability to bypass file permissions on the remote host (for the agent’s U
by munificence 14y ago
From the ssh man page:
Agent forwarding should be enabled with caution. Users with the ability to bypass file permissions on the remote host (for the agent’s UNIX-domain socket) can access the local agent through the forwarded connection. An attacker cannot obtain key material from the agent, however they can perform operations on the keys that enable them to authenticate using the identities loaded into the agent.
- jackalope 14y agoSorry, I didn't mean to suggest that they could obtain the key, just that hijacking the agent was equally dangerous (provided they know where to use it).
- deleted 14y ago[deleted]