logoalt Hacker News

charcircuityesterday at 8:52 PM3 repliesview on HN

If you have ssh installed, with network access it can ssh localhost to escape the sandbox.


Replies

qwertoxyesterday at 9:10 PM

You can consider these agents criminals, or treat them like babies. Both can do harm for a while, but one offers a future.

senkoyesterday at 9:08 PM

Don't give it access to your ssh keys!

show 1 reply
dist-epochyesterday at 9:15 PM

`ssh localhost` doesn't work for me. maybe because I have enabled only key-based ssh and my user key is not in authorized_keys? am I missing something?

show 1 reply