What if I try to login as "bob'; rm -rf /" or some such? Is the system robust against that?
What if I try to login as "bob'; rm -rf /" or some such? Is the system robust against that?
Looking at the escaping function, it will allow $(execute whatever you want), because it doesn't handle $.
https://github.com/openssh/openssh-portable/blob/master/misc...
Anyway, this depends on being able to specify any username, which while possible, requires you to pass the check that user exists in the system, which will be harder.
But it may still be possible if some weird PAM module is used.
https://github.com/openssh/openssh-portable/blob/master/misc...
Because then you'll end up with '$(some)' instead of "$(some)"
https://github.com/openssh/openssh-portable/blob/b52c0c2e649...
There the "command" variable is the result of the function you mention, but here the use is only for logging. The actual argv for the subprocess is the "av" argument which comes from first splitting and then replacing "%u" etc.
But otherwise, yes, you can run any valid command or pipeline on the server side so rm -rf is certainly acceptable.
AuthorizedKeysCommandUser root
I'm pretty sure that is enough permissions to cause trouble.I was just talking about standard ssh behavior.
I wouldn’t use that without seriously studying it end to end. As another comment said, “seems kind of hacky”.
keys = (f"command=\"buildsrht-shell '{b64key}'\",restrict,pty " +
f"{key_type} {b64key} somebody\n")
Now it depends on how b64key is sanitized.