5 ms·
Hey, is it not just a simple honeypot reverse hack ssh server? People understand that reverse hacking can happen when connecting to random ssh server, right?
by 3dedb728-3f77 2mo ago
Hey, is it not just a simple honeypot reverse hack ssh server?
People understand that reverse hacking can happen when connecting to random ssh server, right?
- applfanboysbgon 2mo agoWhat exactly is the mechanism by which you think that an SSH RCE is "simple"?
- bulbar 2mo agoIs that more likely than getting hacked when visiting a website?
- jolmg 2mo agoVisiting a random website is the normal use of HTTP. With SSH, there might be assumptions of connecting to a trusted server you have an account with and likely own. It's not very normal to ssh to a random server.
- teiferer 2mo ago> likely own I don't know how you are using ssh, but most ssh servers that I have connected to in my life, and still do, I don't own. Some of them I barely trust.
- QuantumNomad_ 2mo agoThe ones I connect to the most often from my personal laptop I don’t physically own but I do pay to rent them and I installed the OS on them myself.
- hdgvhicv 2mo agoThe main ones I don’t own are VPS servers from fairly large providers, or GitHub.
- jolmg 2mo agoWhen I said "own", I meant more in the sense of personally administering. It's like how you own a domain, but you're really renting it from a registrar. Rented hardware and VPSs count, as well as other servers/hosts you're responsible for.
- teiferer 2mo agoI got that, and I'm not saying that it doesn't apply to you, but it surely does not apply to everybody.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- singpolyma3 2mo agoThis is simply not true
- xorcist 2mo agoAre we all pretending we have no empirical data on this? How many RCEs has there been in popular web browsers over the past two decades (dozens? hundreds?), compared to how many RCEs there has been in the OpenSSH client (perhaps we can make it one if we include xterm in that)?
- bulbar 2mo agoIt is a real question, because I didn't know about the mentioned ssh attack vector. Regarding empirical data, that would certainly be interesting, not sure if RCE is the only category one would look at in that case.
- scubbo 2mo ago> People understand that reverse hacking can happen when connecting to random ssh server, right? No, actually, I've never heard of such a vector. How would that work?
- krautsauer 2mo agoVulnerability in your ssh client (unlikely) or terminal emulator (more common but lower reach).
- yjftsjthsd-h 2mo agoTerminal emulators have, on occasion, had all kinds of interesting escape codes that I wouldn't want to expose to an attacker. Whether this is even a true "vulnerability" is somewhat a matter of opinion (in the sense that the feature works as designed, but that's maybe a bad thing).
- jerrythegerbil 2mo agoAn ssh server would exploit a vulnerability in the ssh client when it connects. For example, openssh has both a client and server. There’s been vulnerabilities in openssh, in the client. Those vulnerabilities aren’t reachable unless you’re connecting to a server attempting to exploit you, so the risk is quite low because you know and trust most servers you’re connecting to with ssh. To sum it up: Connecting to this server is probably fine, but in doing so most people are doing something significantly riskier without realizing it.
- teiferer 2mo ago> To sum it up: Connecting to this server is probably fine And what are you basing this statement on?
- deleted 2mo ago[deleted]
- applfanboysbgon 2mo ago
- neuroticnews25 2mo agoProve it, I'll connect to any server you point me to, using default openssh client flags.
- UqWBcuFx6NV4r 2mo agoTry me.
- arghwhat 2mo agoPeople understand that such "reverse hacking" can happen when their browser connects to any site (including all the indirect connections from dependent resources), right? Or when resolving any domain name? Or when even just pinging an IP? The risk is far, far lower than browsing the internet. Unlike the massive surface of a browser and all the libraries and processes it is comprised of, the OpenSSH client is a tiny, with a singular purpose, contained in a small and very well-vetted codebase. From the perspective of connecting to a foreign network service, the OpenSSH client is about the safest thing you can possibly use. Note the use of relative words here - not claiming it is 100% bug-free. (The main caveat is that you can manually configure the client to do unsafe things, like writing a configuration by hand that enables X forwarding or agent forwarding by default for any host - but you can also actively disable sandboxing in your web browser or run everything as root, and we will never be able to stop you from actively making things insecure.)
- jolmg 2mo agoThere's also the terminal to consider, via terminal escape sequences.
- arghwhat 2mo agoYes, but terminal escape sequences are a very, very small surface. It's just a few opcodes like "wipe screen", "switch to buffer B", "move to X,Y". All process output regardless of whether it is a terminal escape sequence or regular text just navigate and update the screen "cells", and in, say, alacritty this will be in boring, non-unsafe Rust. For comparison, the surface exposed by your browser rendering this text controlled entirely by an adversary (me) is considerably greater as it also interacts with the style system, content reflow, javascript engine (even for non-javascript websites), etc.
- jeninh 2mo agoWould like to clarify that all my code is open source at https://github.com/jeninh/ssh.place https://github.com/jeninh/ssh.place , even the deployment is triggered through GitHub actions. I'm also a teen and not too familiar with most of these terms, so I might be forgetting something.
- 3dedb728-3f77 2mo agoWhat is public can be changed in private, as for being unfamiliar, well LLM made unfamiliar people able to do plenty of things. Weird that you can't just say that you are not doing it.