2 ms·
SFTP/SCP and other applications that use SSH for transport encryption work by invoking commands once they have a shell on a remote machine. (A user can be given
by afuchs 17y ago
SFTP/SCP and other applications that use SSH for transport encryption work by invoking commands once they have a shell on a remote machine. (A user can be given a shell that limits the commands they can execute to only those needed for such services.)
The problem occurs when an admin does not know what the daemon they are running on their machine does. The article is placing blame on the SSH daemon maintainers for making it easy to run their daemon in a way that exposes features that the admin would not want to knowingly expose.
So blame could be placed on:
* the admins who unintentional leave their machines using such configurations
* the developers of services which function over SSH, for using a design that makes it easy for an admin to unintentionally use such configurations.
* the developers of the SSH daemon for not designing their software to prevent misconfiguration when it is used to encrypt the communication of other services
[excuse me if I sound hostile, I've had a fairly bad day]
- afuchs 17y agoLooking at various docs, I'm not certain that SFTP functions in the same way as SCP/etc. [have to look at this in more depth at another time]