ait-testbed / ait-testbed/attackbed

Make MGMT-Host Secure

Aperta
#8 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
enhancement
Lingua principale
Jinja
Stelle
18
Fork
7
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Descrizione

In scenario1(videoserver) some attacks need actions executed from admin-pc. In order to make those hosts accessible by attackm8, the mgmt-host is allowed to have password-login via ssh. This is insecure in environments where the mgmt-host is hosted with a public ip(public cloudprovider).

I can think of possible solutions like:

1. create another jumphost, that is only for the simulation and has no floating-ip
2. add the inet-network to the adminpcs so that they are dual-homed and can directly accessed by attackm8

Guida per i contributori

Nessuna guida per i contributori indicizzata per questo repository

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.