Do not ignore SSH host validation
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。
ID: go-security/ssh-ignore-keys
Language: Go
Severity: Warning
Category: Security
Description
SSH host validation should never be ignored and always be enforced to avoid man-in-the-middle attacks.
Learn More
Non-Compliant Code Examples
package main
import (
"golang.org/x/crypto/ssh"
)
func main() {
_ = ssh.InsecureIgnoreHostKey()
}
Compliant Code Examples
package main
import (
"golang.org/x/crypto/ssh"
)
func main() {
// not valid in tests
_ = ssh.InsecureIgnoreHostKey()
}
Seamless integrations. Try Datadog Code Analysis