ait-testbed / ait-testbed/attackbed

Make MGMT-Host Secure

未关闭
#8 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
enhancement
主要语言
Jinja
星标
18
派生
7
PR 合并指标
30 天内没有已合并 PR

描述

In scenario1(videoserver) some attacks need actions executed from admin-pc. In order to make those hosts accessible by attackm8, the mgmt-host is allowed to have password-login via ssh. This is insecure in environments where the mgmt-host is hosted with a public ip(public cloudprovider).

I can think of possible solutions like:

1. create another jumphost, that is only for the simulation and has no floating-ip
2. add the inet-network to the adminpcs so that they are dual-homed and can directly accessed by attackm8

贡献指南

这个仓库没有索引到贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。