Mailing List Archive
tlug.jp Mailing List tlug archive tlug Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: [tlug] telnet'ing to home with Java servlet
- Date: Mon, 31 Oct 2005 22:16:59 -0500
- From: Jim <jep200404@example.com>
- Subject: Re: [tlug] telnet'ing to home with Java servlet
- References: <9c414c890510261809u778bc81aq212b7505ccbeb400@example.com> <20051028103654.573c1c95@example.com> <9c414c890510280539o41f25430x17fb74aea831fcf2@example.com> <d8fcc0800510281806x48f387cfi4e855a5a067dea7e@example.com> <9c414c890510281932h597330fy470f60b178de1ded@example.com> <1130569428.4612.16.camel@example.com> <20051031210604.483ce61b.jep200404@example.com> <1130813144.5733.10.camel@example.com>
On Tue, 01 Nov 2005 11:45:43 +0900 Shawn <shawn@example.com> wrote: > 4. enter in your commands (ls, grep, cp whatever) and upload file > with password [to this securely, you'd want a list of disposable > passwords that the servlet checks each time before running the > commands. One time passwords are vulnerable to man-in-the-middle attacks. > Take a copy of the list to work and then send it in]. > Actually, you could just submit the file clear text since it is > disposable but I thought pgping it would hide your password > length. If you did, pgp it, you'd have the ANT file decode the > pgp file. What you have is close to tunneling telnet over http. The security of your approach is robustly broken in manifold ways. > I'd try tunneling myself I think -- just to learn something new. There are Java based tunnels for carrying ssh over http. On the PC at work, one browses to a page on the home computer. That web page downloads Java code for the work browser to execute. That Java code implements a ssh client and then tunnels it over http to the home server. The home server would have more Java stuff for the other side of the http to ssh conversion. Such browser Java clients communicate securely. Their weak link is when the browser downloads the Java client code, a man in the middle could substitute a compromised Java code, so you'd want to use https and the big certificate thing to download the Java client. Dave has not exhausted the simplest approaches, so it is best to wait for him to complete the list of simple things to try in the Occam's Razor letter.
- Follow-Ups:
- Re: [tlug] telnet'ing to home with Java servlet
- From: Shawn
- Re: [tlug] telnet'ing to home with Java servlet
- From: Micheal E Cooper
- References:
- Re: [tlug] SSH'ing to home with Java servlet
- From: Jim
- Re: [tlug] SSH'ing to home with Java servlet
- From: Shawn
Home | Main Index | Thread Index
- Prev by Date: [tlug] Mozilla Colors
- Next by Date: Re: [tlug] telnet'ing to home with Java servlet
- Previous by thread: Re: [tlug] SSH'ing to home with Java servlet
- Next by thread: Re: [tlug] telnet'ing to home with Java servlet
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links