Two-factor authentication
Two-factor authentication
Posted Sep 5, 2011 10:36 UTC (Mon) by sitaram (guest, #5959)In reply to: Two-factor authentication by slashdot
Parent article: kernel.org compromised
If we make the assumption that all 448 users really do not need an actual *shell*, and that they will be mostly doing git push or putting files in some designated area using rsync, you can actually use gitolite to limit what they can do quite handily.
They don't get a shell, their access are limited to whatever repos they've been given access to, and even the rsync command can be access controlled using the same software, limiting users write access to specific directories only.
I've kinda lost track if they found the actual *escalation* vector involved but I'll bet it needed shell on the server.
