TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Bypassing Authentication on SSH Bastion Hosts

101 点作者 aberoham超过 5 年前

7 条评论

oil25超过 5 年前
Characterizing this software feature as an "attack" or "backdoor" is pretty hyperbolic. In order to abuse multiplexing, the adversary needs local code execution ability, by which point you've already lost.
评论 #21518596 未加载
评论 #21518062 未加载
评论 #21518406 未加载
评论 #21521317 未加载
评论 #21517458 未加载
评论 #21518544 未加载
评论 #21518534 未加载
wolf550e超过 5 年前
Why not a patch to openssh to disable multiplexing on the server? At least as an option.
评论 #21517361 未加载
hhii超过 5 年前
In our team, we always use an ssh-agent, and require it to confirm, via popup, each use:<p><a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Ssh-agent#Security_issues" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Ssh-agent#Security_issues</a><p>&gt; There is a procedure that may prevent malware from using the ssh-agent socket. If the ssh-add -c option is set when the keys are imported into the ssh-agent, then the agent requests a confirmation from the user using the program specified by the SSH_ASKPASS environment variable, whenever ssh tries to connect.
评论 #21521556 未加载
mercora超过 5 年前
dont people authenticate indiviually using their own credentials on a common bastion host? that seems quite odd to me and like the actual issue here. if you got root already on the bastion host there are quite a few ways to obtain credentials i would guess...
评论 #21522643 未加载
theamk超过 5 年前
Are there really ssh bastions which allow arbitrary command execution? This seems dangerous.<p>Limiting remote commands to port forwarding only will severely hamper this kind of attack, and will prevent ForwardAgent hacks as well.
评论 #21517417 未加载
评论 #21517186 未加载
kerng超过 5 年前
Seems similar to SSH Agent Hijacking - mostly useful for red teaming only - because you need to compromise the Engineer&#x2F;SRE&#x2F;DevOps person first.
pmoriarty超过 5 年前
Any way to read this article without Javascript?
评论 #21516945 未加载
评论 #21519115 未加载
评论 #21517284 未加载
评论 #21516838 未加载