[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: sudo password visible through ssh command line



On Thu, Jul 10, 2008 at 01:04:31PM +0200, Javier Barroso wrote:
> Hi,
> 
> In sid with key passwordless auth :
> 
> ssh user@server "sudo ls"
> password: password
> 
> And password is shown you

just confirming I see this behavior as well.

> 
> Any tip to avoid this ?

don't issue sudo commands in an ssh command like that. Separate them
into two steps.

> 
> Where should be reported this bug if it could be consider as such (note I
> don't know if there are more programs with this problem)?

I definitely consider that a bug. Who to file against? I don't know.

I don't use ssh this way, so...

Is this new behavior? If so can you pinpoint when it started and
determine from your aptitude logs which package may be involved? 

I can't come up with another program that will prompt for a password
over ssh like that. Su doesn't work at all. 

There is this bug
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=337484 which seems
like it *might* be related. 

If you can't come up with anything more definitive, I would recommend
filing against openssh-client as a starting point. They can likely
pinpoint where the problem is and forward appropriately.

A

Attachment: signature.asc
Description: Digital signature


Reply to: