Lighthouse has a new layout. Prefer the old one? Return to the old layout, and switch back any time from the link at the top of each page.

security issue with AMI?

#27

I note that ./root/.ssh/authorized_keys, in addition to my own key, contains this:

ssh-rsa snip...3qyG8x bbc-keypair

which, I think, means root access for this key's owner on any running VipDAC instance.

Reported by Brian Pratt · April 28th, 2009 @ 12:47 PM

State: resolved
Milestone: high priority
Assigned to: jgeiger jgeiger

Activity

  1. jgeiger
    jgeiger
    • State changed from new to resolved
    • Milestone set to high priority

    That public key is owned by me, and should have been removed on build. I've updated the build script in the source code to remove the key on cleanup.

    While it technically does allow me access to your running instance, I would have to know the ip/dns name provided by amazon when it was launched, which is near impossible unless you provide that information to me.

    Thank you for the report.

    April 28th, 2009 @ 01:21 PM

  2. Brian Pratt
    Brian Pratt

    Yeah, a pretty minimal risk - I just thought you'd want to know before some end user freaks out about a finding a backdoor on their system. Perceptions around security issues are something we need to be pretty tweaky about when building public AMIs if we want folks to embrace the cloud.

    April 28th, 2009 @ 01:49 PM

Please Sign in or create a free account to add a new ticket.

With your very own profile, you can contribute to projects, track your activity, watch tickets, receive and update tickets through your email and much more.