ait-testbed / ait-testbed/attackbed
Make MGMT-Host Secure
Đang mở
enhancement
- Ngôn ngữ chính
- Jinja
- Star
- 18
- Fork
- 7
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Mô tả
In scenario1(videoserver) some attacks need actions executed from admin-pc. In order to make those hosts accessible by attackm8, the mgmt-host is allowed to have password-login via ssh. This is insecure in environments where the mgmt-host is hosted with a public ip(public cloudprovider).
I can think of possible solutions like:
1. create another jumphost, that is only for the simulation and has no floating-ip
2. add the inet-network to the adminpcs so that they are dual-homed and can directly accessed by attackm8
Hướng dẫn đóng góp
Chưa lập chỉ mục được hướng dẫn đóng góp cho kho mã nguồn này
Đánh giá
Issue này chưa được đánh giá.