[Techtalk] Securely transferring files using scripts

Jenn Vesperman jenn at anthill.echidna.id.au
Sun Jul 21 03:38:31 EST 2002


On Sun, 2002-07-21 at 03:00, jennyw wrote:
> Thanks, Hamster!  But if I do that, and if the box with the script gets
> compromised, won't that give an intruder full access to the second box,
> too?  That's what I want to avoid. 

That's why a daemon runs the script. The daemon has a name which is a
null - a nonentity with no permissions - on the remote machine.

I'm not sure of the specifics, but I suspect that a /bin/false shell
would do much of the protection.


Jenn V.
-- 
    "Do you ever wonder if there's a whole section of geek culture 
        	you miss out on by being a geek?" - Dancer.

jenn at anthill.echidna.id.au     http://anthill.echidna.id.au/~jenn/





More information about the Techtalk mailing list