bugzilla-daemon at bugzilla.mindrot.org
2007-Nov-27 12:09 UTC
[Bug 1394] New: SCP used to overwrite key
https://bugzilla.mindrot.org/show_bug.cgi?id=1394 Summary: SCP used to overwrite key Classification: Unclassified Product: Portable OpenSSH Version: 4.7p1 Platform: Other OS/Version: Linux Status: NEW Severity: normal Priority: P2 Component: scp AssignedTo: bitbucket at mindrot.org ReportedBy: FoxDie7987 at gmail.com Hi, I don't know if this is a bug, but I have been searching in Google and the project's web, and I haven't found anything. I think that I haven't found anything because my bad English, but I put this here because I don't know what to do. I'm using an up to date Gentoo 2007.0, with openssh 4.7-r1 (marked as stable), and ssh with a key with passphrase. I have found that if I do an "scp key.pub user at hostname:/home/user/.ssh/authorized_keys", scp ask me for the user password and not for the key, so if I know the password of the user, I can overwrite the key and get the control of that machine. I don't know if this is a problem of my configuration (same as Gentoo default, but without permission of root and password login), a patched version of the Gentoo team, or of the original version. Thanks, and sorry if I'm wrong and I have made that the person who reads this wastes his time. Sorry also for my mistakes, as I mentioned above, I have a bad English but I'm trying to improve it. -- Configure bugmail: https://bugzilla.mindrot.org/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are watching the assignee of the bug.
bugzilla-daemon at bugzilla.mindrot.org
2007-Nov-27 13:41 UTC
[Bug 1394] SCP used to overwrite key
https://bugzilla.mindrot.org/show_bug.cgi?id=1394 Joel <FoxDie7987 at gmail.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution| |INVALID -- Configure bugmail: https://bugzilla.mindrot.org/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are watching the assignee of the bug.
bugzilla-daemon at bugzilla.mindrot.org
2008-Apr-03 23:01 UTC
[Bug 1394] SCP used to overwrite key
https://bugzilla.mindrot.org/show_bug.cgi?id=1394 Damien Miller <djm at mindrot.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|RESOLVED |CLOSED --- Comment #1 from Damien Miller <djm at mindrot.org> 2008-04-04 10:01:26 --- Close resolved bugs after release. -- Configure bugmail: https://bugzilla.mindrot.org/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are watching the assignee of the bug.
Maybe Matching Threads
- [Bug 1368] New: avoid "scp not found" with option to specify remote scp command
- [Bug 1436] New: scp -p does not preserve sticky bit (01000)
- [Bug 1362] New: Scp should not follow links
- [Bug 1172] [PATCH] Restrict public key authentication to scp access only
- [Bug 2005] New: scp should not overwrite files (without confirmation)