PDA

View Full Version : SCP/SFTP (yes AGAIN !!!)


zero
9-1-05, 01:50 PM
So I've read through all the past threads regarding scp/sftp and have some comments and a request.

I saw in several threads where a PowWeb staff member said the only way an account/password would get sniffed was if the PowWeb server got compromised. They also went on to make mention of PowWeb being on a switched network as opposed to hubs, and also mentioned the kernel on the machines being compiled without a packet sniffing module installed. This idea is completely bogus. Are they just ignoring the FACT that FTP/POP/etc. are two way communications and that the account can get compromised at the initiation point, a place like a customers cable/dsl/dial-up network, and ANY point between the two?

Not having shells on the servers has been the other argument. Well there is a way for PowWeb to offer sftp/scp without granting shell access. There is a tool called scponly that allows users access to their files via scp/sftp and it even does chrooting into their directory so they can't even see the directory structure above.

Any chance sftp/scp can finally be offered with this tool I've pointed out?
http://sublimation.org/scponly/

zero
9-2-05, 12:42 PM
Nearly 24 hours and no response. A simple yes, no, or we'll look into it would be nice.