Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: How to verify Privilege Separation is working? |
|---|---|
| Date: | Fri, 22 Oct 2004 10:08:26 +0100 |
Thanks!
- Philip
David Walker wrote:
ssh into your server to an account that requires a password or a non-existing account that prompts for a password. Don't enter a password at this time but run your ps command (from another shell of course). If privilege separation is operational then you will see an sshd process running under the separation account such as "sshd"
On Friday 24 September 2004 02:59 am, Philip Le Riche wrote:
Hi -
Is there a simple way to positively demonstrate that privilege separation is working? Running ps -fe shows all sshd processes running as root. If /var/empty doesn't exist, sshd still seems to work, but presumably without privilege separation. There may be other configuration errors which could have the same effect.
(The reason I ask is that a vulnerability assessment has shown that I need to upgrade to OpenSSH 3.7.1 to avoid known vulnerabilities. However, rebuilding from source has run into problems with incompatible libraries since we're on an old version of AIX. No doubt these are fixable, given time my management may not allow me, but if I could positively demonstrate that privilege separation is working, I could argue that the risk is low and limited to DoS. Agreed?)
- Philip
******************************************************* This email has originated from Steria Limited, Registration No: 2706218.
Privileged, confidential and/or copyright information may be contained in this email, and is only for the use of the intended addressee. To copy, forward, disclose or otherwise use it in any way if you are not the intended recipient or responsible for delivering to him/her is prohibited.
If you receive this email by mistake, please advise the sender immediately, by using the reply facility in your email software.
We may monitor the content of emails sent and received via our network for the purposes of ensuring compliance with policies and procedures.
This message is subject to and does not create or vary any contractual relationships between Steria Limited and the recipient.
Office registered at: Three Cherry Trees Lane, Hemel Hempstead, Hertfordshire, HP2 7AH www.steria.co.uk ******************************************************
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: Controlling ssh from an external program, Frank Hamersley |
|---|---|
| Next by Date: | RE: SSH and mounted home directories, Covington, Jimmy D. (NGIT) |
| Previous by Thread: | Re: How to verify Privilege Separation is working?, Philip Le Riche |
| Next by Thread: | Re: How to verify Privilege Separation is working?, Jerry |
| Indexes: | [Date] [Thread] [Top] [All Lists] |