ait-testbed / ait-testbed/attackbed

Make MGMT-Host Secure

未關閉
#8 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
enhancement
主要語言
Jinja
星號
18
分支
7
PR 合併指標
30 天內沒有已合併 PR

描述

In scenario1(videoserver) some attacks need actions executed from admin-pc. In order to make those hosts accessible by attackm8, the mgmt-host is allowed to have password-login via ssh. This is insecure in environments where the mgmt-host is hosted with a public ip(public cloudprovider).

I can think of possible solutions like:

1. create another jumphost, that is only for the simulation and has no floating-ip
2. add the inet-network to the adminpcs so that they are dual-homed and can directly accessed by attackm8

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。