LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-22-2006, 04:29 PM   #1
MrSako
Member
 
Registered: May 2006
Distribution: CentOS 4.4
Posts: 185

Rep: Reputation: 30
accessing via ssh login


im creating a web based control panel in PHP, its meant to interact with game servers, and some of its features need for the script to connect via ssh to the server. this is supposed ot be a feature (all the user has to do is create a user account for the contorl panel on their server and thats all the installation needed)

but just giving someone ssh access to their server, im not sure how most people will take that. Though it's not different really from putting on client software on their machine (as far as risks) i think people will just be scared to create ssh access.

im bassicaly asking for tips to make the system sound more safe. is there user limits that the client can said for the ssh login user to limit what it can do.

Id like to include a "safety" type thing for what settings can produce the most secure results.

also any other ideas and such are very welcome id just like to get some outside input on this
 
Old 12-23-2006, 06:54 AM   #2
live_dont_exist
Member
 
Registered: Aug 2004
Location: India
Distribution: Redhat 9.0,FC3,FC5,FC10
Posts: 257

Rep: Reputation: 30
If I understand this correctly the users are going to use this web based control panel to connect to the game servers. The connection that happens is based on Ssh.

If its webbased then users are going to be connecting to this web based server and then connect to the game servers..right?? If yes then you can do the creation of the user account yourself..all the users will have to do is select the server they want to log in to and click "Connect" and the ssh'ing will happen internally.

That apart you'd definitely want to harden your webserver and also allow only specific users to access your webbased control panel. There's loads of guides available.

Hope I didnt misunderstand what you needed Plz post back if thats the case.

Cheers
Arvind
 
Old 12-28-2006, 02:18 PM   #3
MrSako
Member
 
Registered: May 2006
Distribution: CentOS 4.4
Posts: 185

Original Poster
Rep: Reputation: 30
i mean,
im not going to have a control panel client on their machines. im going to tell them to make access to the server via ssh and submit the ssh login information to my script which gets encrypted into my database.

and the script will login to their server via ssh to install game servers and do all the stuff a control panel should do

just i dont know how willing people will be to create ssh users for things like that since its not very common
 
Old 12-28-2006, 02:50 PM   #4
chort
Senior Member
 
Registered: Jul 2003
Location: Silicon Valley, USA
Distribution: OpenBSD 4.6, OS X 10.6.2, CentOS 4 & 5
Posts: 3,660

Rep: Reputation: 76
That's begging for a rooted box. One of the most important rules in security is to never give anyone else your login information. There's really no "secure" way to do it. Sure, your customers could create a highly restricted account and lock down their sshd, but if they're simply running game servers there's little chance that they'll know how to do such a thing, or want to spend the time doing it.

Isn't there any way you could simply install an agent on the user's server that would collect the necessary information and send it back to your control panel? That seems like a much healthier approach. It will also work through NAT, which your proposed ssh login wouldn't (without additional configuration by the customer).
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
problem in accessing the server using ssh gauri Debian 1 01-17-2006 10:56 PM
Accessing pc with putty (ssh) Wozl Linux - Networking 1 10-10-2005 03:44 PM
Accessing tty1 from ssh. dlublink Mandriva 2 10-07-2004 10:28 PM
Accessing SSH thru the net. TRi-x2 Linux - Security 5 03-28-2004 07:48 AM
Problems accessing server using ssh client. rmc Linux - Networking 1 12-12-2002 02:01 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:39 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration