From owner-freebsd-current@FreeBSD.ORG Wed Sep 12 14:33:20 2007 Return-Path: Delivered-To: freebsd-current@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 6AB0B16A419 for ; Wed, 12 Sep 2007 14:33:20 +0000 (UTC) (envelope-from bsam@ipt.ru) Received: from mail.ipt.ru (mail.ipt.ru [194.62.233.102]) by mx1.freebsd.org (Postfix) with ESMTP id 1972813C48D for ; Wed, 12 Sep 2007 14:33:20 +0000 (UTC) (envelope-from bsam@ipt.ru) Received: from doc.sem.ipt.ru ([192.168.12.1] helo=ipt.ru) by mail.ipt.ru with esmtp (Exim 4.62 (FreeBSD)) (envelope-from ) id 1IVTHK-000EAo-DT for freebsd-current@FreeBSD.org; Wed, 12 Sep 2007 18:33:18 +0400 Received: from bsam by ipt.ru with local (Exim 4.63 (FreeBSD)) (envelope-from ) id 1IVTIV-0001MZ-RY for freebsd-current@FreeBSD.org; Wed, 12 Sep 2007 18:34:31 +0400 To: freebsd-current@FreeBSD.org From: Boris Samorodov Date: Wed, 12 Sep 2007 18:34:31 +0400 Message-ID: <89849832@srv.sem.ipt.ru> User-Agent: Gnus/5.11 (Gnus v5.11) Emacs/22.0.99 (berkeley-unix) MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: Subject: sshd and a "command" option at ~/.ssh/authorized_keys X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 12 Sep 2007 14:33:20 -0000 Hi! With 'command="/bin/echo You are $USER!"' at ~/.ssh/authorized_keys: $ ssh You are duser! <-- is'a real username But with 'command="/bin/echo You invoked $SSH_ORIGINAL_COMMAND!"': $ ssh You invoked ! ^^^^^^^^^^^^^ Is this a bug? (Yes, I know about security issues etc.) If I use a script at the "command", the invoked command is shown. The man page says: ----- The command originally supplied by the client is available in the SSH_ORIGINAL_COMMAND environ- ment variable. Note that this option applies to shell, command or subsystem execution. ----- The system is (from Sep 02): $ uname -srm FreeBSD 7.0-CURRENT amd64 Thanks! WBR -- Boris Samorodov (bsam) Research Engineer, http://www.ipt.ru Telephone & Internet SP FreeBSD committer, http://www.FreeBSD.org The Power To Serve