Re: multiuser sshd as non-root

[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

 



On Mon, 5 Aug 2019 at 20:26, Adam Endrodi <endrodi@xxxxxxxxx> wrote:
[...]
> My question is, do you think such a use case (running multiuser sshd as
> non-root) is possible theoretically, or can it be implemented with a
> small patch?

I suspect it will not work out of the box, because there are a number
of checks of the form (this one is from uidswap.c):

        if (geteuid() != 0) {
                privileged = 0;
                return;
        }

I also suspect it could be made to work with a relatively small set of
changes.  For a proof of concept I'd suggest you try changing all of
the instances of "privileged = 0" to "privileged = 1" in uidswap.c
(this would not be suitable for real use, though).

-- 
Darren Tucker (dtucker at dtucker.net)
GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860  37F4 9357 ECEF 11EA A6FA (new)
    Good judgement comes with experience. Unfortunately, the experience
usually comes from bad judgement.
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@xxxxxxxxxxx
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev



[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[Index of Archives]     [Linux ARM Kernel]     [Linux ARM]     [Linux Omap]     [Fedora ARM]     [IETF Annouce]     [Security]     [Bugtraq]     [Linux]     [Linux OMAP]     [Linux MIPS]     [ECOS]     [Asterisk Internet PBX]     [Linux API]

  Powered by Linux