LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-30-2007, 05:18 AM   #1
assasukasse
Member
 
Registered: Mar 2006
Location: UK
Distribution: Debian, Ubuntu
Posts: 141

Rep: Reputation: 15
ssh tricks for http forwarding..


Hi everyone
i have a pc at home running linux and online 24/24.
I also have a friend that works in a company restricting his internet access.
now i wish to give this friend the chance to see the whole internet using my pc as a gateway by ssh tunneling, however i don't want to give him shell account.
For my ssh i use RSA authentication, and it works wonderfully, but i have shell access, in order to make an user w/o shell access i did this:

#adduser --no-create-home --shell /bin/false httpssh

but when i try to redirect i get an error about the pubkey..how should i deal with that? can i disable pubkey for ONLY this account? or should i generate a pubkey for this account as well? and how should i do that?

thank you very much
 
Old 09-30-2007, 05:54 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by assasukasse View Post
I also have a friend that works in a company restricting his internet access.
For generating keys see "man ssh-keygen". I need to warn you however that deliberate circumvention can have severe repercussions. Those network policies aren't in place w/o reason. Since you will allow your "friend" to use your system, any investigation will lead to you with no chance to cloak yourself (w/o performance drop) since we're talking TCP and you can certainly be held responsable in case damages arise. Think twice, I'd say.
 
Old 09-30-2007, 06:20 AM   #3
assasukasse
Member
 
Registered: Mar 2006
Location: UK
Distribution: Debian, Ubuntu
Posts: 141

Original Poster
Rep: Reputation: 15
unSpawn, my friend wants only to access his Gmail and guns&ammo forum..nothing more than that..
i could even restrict him to only those two websites and it would be already good
for generating keys, if i make an httpssh user on my computer
he needs to generate a pubkey for the same user on his pc, if he uses windows no problem, he can use puttygen.
but in case he is on linux, what should he do?
make an user with that name? generate the key, then remove the user?
because i couldn't find in ssh-keygen a way to generate a key for an user that is not on the system
 
Old 09-30-2007, 06:38 AM   #4
stress_junkie
Senior Member
 
Registered: Dec 2005
Location: Massachusetts, USA
Distribution: Ubuntu 10.04 and CentOS 5.5
Posts: 3,873

Rep: Reputation: 335Reputation: 335Reputation: 335Reputation: 335
I would repeat what unspawn said. Plus I would add that this is hacker stuff whatever your intention might be. That makes it illegal as well as breaking the employer's network policy. If you are in the United States you could go to prison for trying to do this.

And ... it is against the policies of this site to assist hackers.

Last edited by stress_junkie; 09-30-2007 at 06:41 AM.
 
Old 09-30-2007, 07:35 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by assasukasse View Post
my friend wants only to access his Gmail and guns&ammo forum..nothing more than that..
Then your "friend" should have no problem in the first place convincing management that private email and forum banter pose no threat to productivity or company security and getting paid for it is cool as well. As far as your username "problem": you're using GNU/Linux which means you already posess all the information you need to make it work and you can experiment freely. Coming up with a simple way to test using different usernames should not be hard.


Understand that when you signed up for a LQ account you agreed to adhere to the LQ Rules.
Unfortunately you have shown you don't mind the risks and don't understand your responsabilities.
Therefore please note that if you continue this thread it *will* be closed faster than you can 'ssh-keygen'.

Last edited by unSpawn; 09-30-2007 at 07:38 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH tricks -- any way to block failed attempts by IP address tensigh Linux - Security 10 06-06-2008 03:46 PM
http port forwarding sanjibgupta Linux - Networking 2 04-27-2007 01:02 PM
LXer: Advanced SSH security tips and tricks LXer Syndicated Linux News 0 03-30-2007 03:16 PM
Stupid networking tricks: X11 forwarding and hosts.deny Randux Slackware 24 09-22-2006 05:06 AM
Forwarding HTTP esquilo Linux - Networking 7 06-17-2005 02:47 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:21 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration