back
2 comments
That's a feature, not a bug. SSH is a power tool; if your users can not be trusted with power tools, it is your responsibility to provide them with something brightly coloured, drool-proof and locked down.
Then how do you exploit it without assuming the ability to execute arbitrary code as the user?
Some time soon I will put something up on github so you can test this methodology. It probably won't be tonight though.