Re: ssh



On 10/31/07, James <oscartheduck@xxxxxxxxx> wrote:



On 10/31/07, Michael Grant <mg-fbsd3@xxxxxxxxx> wrote:

If I'm sued as root and I ssh somewhere, ssh/scp reads it's files from
/root/.ssh/. The docs say it reads from ~/.ssh which is what I want,
but it's not doing that. When sued, the shell is properly expanding ~
to my home dir.

Anyone know of a way around this behavior?

Michael Grant


su - root

Nope. One other suggestion was 'su -l root'. This does not change
the situation either.

I went into the source for ssh and it does a getuid() and then gets
the homedir of that uid. So no amount of fooling with su is gonig to
fix this. I guess it's like this for security reasons, it sure seems
like a bug to me. I'd have used the HOME enviroment variable.

So far, the best fix I've found is to create some aliases in bash as follows:

alias scp="scp -o User=username -i ~/.ssh/id_rsa"
alias ssh="ssh -l username -i ~/.ssh/id_rsa"
alias rsync="rsync -op -e 'ssh -l username -i /home/username/.ssh/id_rsa'"
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • RE: Linux hacked
    ... Also, what exactly did the history file show, can you paste it into a mail ... > First let me say I'm a security novice. ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
    (Security-Basics)
  • Re: a program to set up a secure private network?
    ... > possible to really explain what he needs to fix in order to use his web ... > root because some of the configuration I would do involves with root ... It would also needed that I access to his computer in GUI ... but you don't know about ssh? ...
    (alt.linux)
  • Re: Linux hacked
    ... To find out what kernel version you are running, type "uname -a" without ... > been unsuccessful in getting root back. ... > via ssh but you could su in once logged in as one of three users. ...
    (Security-Basics)
  • Re: a program to set up a secure private network?
    ... > possible to really explain what he needs to fix in order to use his web ... > root because some of the configuration I would do involves with root ... > mode since in order to configure 'mozilla browser', ... I know that a bunch of people have suggested VNC, but I suggest `ssh -c ...
    (alt.linux)
  • RE: Linux hacked
    ... hack the box, pull the drive and save it. ... Use the newest versions of Gentoo, Apache, SSH, PHP and Squirl Mail. ... been unsuccessful in getting root back. ... I found a hidden directory /var/tmp/.tmp that has a bunch of directories ...
    (Security-Basics)