fmII
Fri, Jul 18th home | browse | articles | contact | chat | submit | faq | newsletter | about | stats | scoop 19:32 UTC
in
Section
login «
register «
recover password «
[Project] add release | add branch | add screenshot | broken links | change owner | email subscribers | update project | update branch (urls) [Project]

 Silk Tree - Default branch
Section: Unix

 

Added: Mon, May 5th 2008 22:54 UTC (2 months, 14 days ago) Updated: Tue, May 6th 2008 10:26 UTC (2 months, 13 days ago)


About:
Silk Tree propagates /etc/passwd and /etc/group files from a master to a list of hosts via SSH. The sending and receiving ends connect to each other as a non-root user. A read-only sudo program on the receiver's side makes the final modifications in /etc. Many checks are made to ensure reliable authorization updates. ACLs are used to enforce a simple security policy. Differences between old and new versions are shown. Two small scripts are included for exporting LDAP users and groups.

Author:
Aleksandr O. Levchuk [contact developer]

Rating:
(not rated)

Tar/GZ:
http://bioinfo.ucr.edu/~alevchuk/silktree-0.0.1.tar.gz

Trove categories: [change]
[Development Status]  5 - Production/Stable
[License]  OSI Approved :: GNU General Public License v3
[Programming Language]  Ruby
[Topic]  Security, System :: Networking :: LDAP

Dependencies: [change]
Portable OpenSSH (required)
Ruby (required)
[download links]

 
Project admins: [change]
» Aleksandr O. Levchuk (Owner)

» Rating: (not rated)
» Vitality: 0.00% (Rank 25009)
» Popularity: 0.11% (Rank 34014)

project statsdownload stats
(click to enlarge graphs)
   Record hits: 944
   URL hits: 144
   Subscribers: 3

Other projects from the same categories:
OpenCA
SSHVnc
ssh-multiadd
renattach
MyEasyMarket

Users who subscribed to this project also subscribed to:
WMTimer
xfirelib
Ryan's Anti-Virus Recipe
Kimai
comhit


Add comment · Rate this project · Subscribe to new releases · Ignore this project · Email this project to a friend · Project record in XML

 Branches

Branch Version Last release License URLs
Default 0.0.1 06-May-2008 GNU General Public License v3 Tar/GZ

 Comments

[»] Is Silk Tree secure?
by Aleksandr O. Levchuk - May 8th 2008 11:47:04

The answer is no.

Silk Tree is an attempt to isolate the receiver side from the
sending side (master host), so that if the sending
side is compromised then the other side stays unaffected.

This goal is not archived because if the adversary is able
to ssh into the receiving side as the silktree user
then the adversary is able to push anything into the
/etc/passwd and /etc/group of the receiver.

The sending side is isolated from the receiving side
because of the one-way design of SSH and I am
careful not to start executing any data that is
gathered from the receiving side.

Having this said, I would still prefer Silk Tree over the
SSHing-as-root method.

--
-------------------------------------------- Aleksandr Levchuk University of California, Riverside 1-951-368-0004 --------------------------------------------

[reply] [top]




© Copyright 2008 SourceForge, Inc., All Rights Reserved.
About freshmeat.net •  Privacy Statement •  Terms of Use •  Trademark Guidelines •  Advertise •  Contact Us • 
ThinkGeek •  Slashdot  •  ITMJ •  Linux.com •  NewsForge  •  SourceForge.net  •  Surveys •  Jobs •  PriceGrabber