|
|
ssh:// Protocol Handler, Updated
Specifically, it seems all arguments to the ssh:// and telnet:// protocol handlers are stripped. While there was never an ssh-specific threat, this seems to be a case of generalized protection against the telnet:// vulnerability. Fortunately, the work-around is simple. Instead of specifying your login name via the It no longer seems possible to specify arbitrary commands to execute (upon successful ssh login), from a stock ssh:// url. Turns out that I never used it anyway, and perhaps now Stefan can breath a little easier... Saturday, June 19, 2004
|
Contact Me Topics RSS Feed Linkblog
Bill Bumgarner Brent Simmons Daniel Jalkut Dave Dribin Eric Albert Eric Rescorla Eric Sink Greg Miller Gus Mueller Jeremy Zawodny John Gruber Mark Dalrymple Michael Tsai Peter Ammon Raymond Chen Ryan Wilcox Scott Stevenson Steven Frank The Daily WTF we hates software Wil Shipley |
Copyright © 1997-2008 Jonathan 'Wolf' Rentzsch. All rights reserved.
Questions? Comments? Contact Me.