Gnus development mailing list
 help / color / mirror / Atom feed
From: Felix Lee <flee@teleport.com>
Cc: ding@gnus.org
Subject: Re: ssh rulez
Date: Sun, 29 Mar 1998 12:38:30 -0800	[thread overview]
Message-ID: <199803292036.MAA19786@mail1.teleport.com> (raw)
In-Reply-To: Your message of 29 Mar 1998 14:12:13 CST. <m2n2e9i7du.fsf@twocups.tanet.net>

> Is that true?  I thought the whole point of ssh/sshd was allow secure
> remote access through encryption, and host/user verification by encrypted
> keys.

yes, but there's no access control to the forwarded port.
if port 119 on your machine is being forwarded somewhere,
all the traffic between you and the somewhere is encrypted
and compressed, etc, but ssh doesn't care who connects to
port 119 on your local machine.

forwarded connections (like the X forwarding) typically rely
on end-to-end user authentication (like xauth) to be secure.
however, nntp authentication tends to be weak, and often
relies on "source" IP address, which looks like it's you if
you're using forwarding.

it shouldn't be too hard to add to ssh a flag that says,
"don't accept connections at the forwarding port unless they
come from a particular IP address", but I don't see such a
thing (in 1.2.20 at least.  haven't looked at newer yet.)
--


  reply	other threads:[~1998-03-29 20:38 UTC|newest]

Thread overview: 18+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
1998-03-28  8:16 Lars Magne Ingebrigtsen
1998-03-28 16:43 ` Harry Putnam
1998-03-28 17:14   ` Bud Rogers
1998-03-28 19:17 ` Richard Hoskins
1998-03-29  8:04   ` Lars Magne Ingebrigtsen
1998-03-29 19:39     ` Felix Lee
1998-03-29 20:12       ` Bud Rogers
1998-03-29 20:38         ` Felix Lee [this message]
1998-03-30 20:05           ` Richard Hoskins
1998-03-29 21:36         ` Alan Shutko
1998-03-30 13:01           ` Robert Bihlmeyer
1998-03-31 16:37 ` Francois Felix Ingrand
1998-04-01 14:06   ` Lars Magne Ingebrigtsen
1998-03-31 21:46 ` Manoj Srivastava
1998-04-15  3:50 ` Eze Ogwuma
1998-04-22 18:27   ` Eric Hendrickson
1998-04-26 11:44     ` Eze Ogwuma
1998-07-12 19:07       ` Eric D. Hendrickson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=199803292036.MAA19786@mail1.teleport.com \
    --to=flee@teleport.com \
    --cc=ding@gnus.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).