3 ms·
Well, it prevents your private key from being compromised but an attacker with root on the intermediate box can still authenticate to other servers using your S
by m-app 12y ago
Well, it prevents your private key from being compromised but an attacker with root on the intermediate box can still authenticate to other servers using your SSH agent socket.
If you really want to do secure SSH hopping, use the ProxyCommand directive with `netcat` in your SSH config.[1]
[1]: http://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#ProxyCommand_with_Netcat http://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Ju...
- Canada 12y agoNice. Thanks for sharing