09-03-2008
Yep. I worked for the DOC and before audit we settled on the CIS L1 standard.
It sounds like you guys went way past that.
I feel your pain but admins that have root create huge problems in a naively secure environment.
Say I su root. The local syslog daemon sends a message to the central logserver (which I have no privileges on) that I have assumed root. Voila..I am accountable. After that any message from that host is not reliable...even that I've logged out. That's the gotcha.
If the level of insecurity is such that admins are allowed root or application equivalence then anything they do is a potential systems compromise.
It's about trust..and all security, large and small, is eventually about trust.
9 More Discussions You Might Find Interesting
1. Programming
Please post a C code for implementation of Memory Mapping function.
It should simulate the mmap command. (1 Reply)
Discussion started by: raviviolet13
1 Replies
2. Shell Programming and Scripting
I was looking at a library that lets me parse comma delimited csv files without a problem, but unfortunately, I'm not allowed to make use of that library. I understand that the library probably does something similar to a string split(), but I don't quite know what kind of regular expression is... (1 Reply)
Discussion started by: mrwatkin
1 Replies
3. Programming
Hi all,
Can some one provide me a sample program which measures the performance (both latency and throughput) of TCP and UDP protocol (2 Replies)
Discussion started by: magnetpest2k7
2 Replies
4. Solaris
I'm trying to find an api for Java to send/receive files via sftp. There are some available for purchase out there such as JScape, but I was hoping to find a free one.
Does anyone know of one?
I would also like to find an open source java example application that can send files via sftp.
... (2 Replies)
Discussion started by: JohnRodey
2 Replies
5. UNIX for Advanced & Expert Users
Hi,
I am using SFTP for transferring files to remote server. Below is the snipped i am using for my sftp program
echo "lcd $i_localdir">/tmp/sftp_Batch
echo "cd $i_destdir">>/tmp/sftp_Batch
echo "put $i_filename">>/tmp/sftp_Batch
echo "chmod 644... (2 Replies)
Discussion started by: Ankgne
2 Replies
6. Shell Programming and Scripting
Hi,
We are getting the following error code while connection remote server using sftp command.
sftp user@serrver
Warning: child process (/opt/ssh2/bin/ssh2) exited with code 126.
pls Advise. (2 Replies)
Discussion started by: koti_rama
2 Replies
7. Shell Programming and Scripting
Hi all
I need to write shell script to list out the mounted devices for a particular user. As i am new to shell script please help me. Here the problem is sometime unmounted devices also will be displayed in fstab. How to rectify that? Can anybody help me?
Regards
Ilamathi (0 Replies)
Discussion started by: ilamathi
0 Replies
8. UNIX for Dummies Questions & Answers
So we know that Unix is free source software. And we know that Unix have support for FAT 16 and FAT 32. Does anyone know where can I found that implementation in code ?
Thank you. (2 Replies)
Discussion started by: medolina
2 Replies
9. Shell Programming and Scripting
hi gurus ,
i want the command to get the output in the desired format .
basically to convert columns to rows.
please refer to the attachment. (3 Replies)
Discussion started by: r_t_1601
3 Replies
LEARN ABOUT SUSE
sftp-server
SFTP-SERVER(8) BSD System Manager's Manual SFTP-SERVER(8)
NAME
sftp-server -- SFTP server subsystem
SYNOPSIS
sftp-server [-ehR] [-f log_facility] [-l log_level] [-u umask]
DESCRIPTION
sftp-server is a program that speaks the server side of SFTP protocol to stdout and expects client requests from stdin. sftp-server is not
intended to be called directly, but from sshd(8) using the Subsystem option.
Command-line flags to sftp-server should be specified in the Subsystem declaration. See sshd_config(5) for more information.
Valid options are:
-e Causes sftp-server to print logging information to stderr instead of syslog for debugging.
-f log_facility
Specifies the facility code that is used when logging messages from sftp-server. The possible values are: DAEMON, USER, AUTH,
LOCAL0, LOCAL1, LOCAL2, LOCAL3, LOCAL4, LOCAL5, LOCAL6, LOCAL7. The default is AUTH.
-h Displays sftp-server usage information.
-l log_level
Specifies which messages will be logged by sftp-server. The possible values are: QUIET, FATAL, ERROR, INFO, VERBOSE, DEBUG, DEBUG1,
DEBUG2, and DEBUG3. INFO and VERBOSE log transactions that sftp-server performs on behalf of the client. DEBUG and DEBUG1 are
equivalent. DEBUG2 and DEBUG3 each specify higher levels of debugging output. The default is ERROR.
-R Places this instance of sftp-server into a read-only mode. Attempts to open files for writing, as well as other operations that
change the state of the filesystem, will be denied.
-u umask
Sets an explicit umask(2) to be applied to newly-created files and directories, instead of the user's default mask.
For logging to work, sftp-server must be able to access /dev/log. Use of sftp-server in a chroot configuration therefore requires that
syslogd(8) establish a logging socket inside the chroot directory.
SEE ALSO
sftp(1), ssh(1), sshd_config(5), sshd(8)
T. Ylonen and S. Lehtinen, SSH File Transfer Protocol, draft-ietf-secsh-filexfer-00.txt, January 2001, work in progress material.
HISTORY
sftp-server first appeared in OpenBSD 2.8.
AUTHORS
Markus Friedl <markus@openbsd.org>
BSD
January 9, 2010 BSD