Re: Restricted Shells or Menu Based Shells

From: Richard Garand (richard@garandnet.net)
Date: 02/26/02


From: Richard Garand <richard@garandnet.net>
To: Terrence Martin <twm139@its.to>
Date: Tue, 26 Feb 2002 12:30:22 -0600


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> On Wed, Feb 20, 2002 at 03:23:21PM -0700, Terrence Martin wrote:
> > Can anyone recommend a good restricted or menu based shell?
> >
> > What I am looking for is a shell that will allow users to run a small set
> > of commands. For example

When I was setting up a secure CVS server, the instructions sais to use the
sendmail restricted shell (smrsh) to restrict the commands that can be run.
It comes with sendmail and if you don't have it you can get it from the
sendmail source (unfortunately I had to compile the entire package to get it,
but with some hacking it might be possible to only compile the shell).
- --
Richard Garand - r i c h a r d @ g a r a n d n e t . n e t
(L)ICQ: 12190132 - http://www.garandnet.net
"The C Programming Language -- A language which combines the flexibility of
assembly language with the power of assembly language."
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8e9Q+juZKnjxs0fMRAsp5AJsFYRtXImFN4aSIRd2rUnh1+S3kkgCgjpbf
eFSRpEFMptPsCTG+fRK1yFo=
=8Mjo
-----END PGP SIGNATURE-----



Relevant Pages

  • Announce: BDB-BASIC Release 0.60 Released
    ... This change does not restrict or alter your ... choose to create/execute in the interpreter. ... INPUT and OUTPUT (for CSV format I/O) ... in shell I/O redirected fashion if required. ...
    (comp.lang.basic.misc)
  • Re: Restrict to home dir
    ... I can't think of any accasion where I would allow them outside of thier own ... >>way to restrict them to thier own directory. ... > 2) The possibility priviledge elevation ... > by a knowlegable user with a shell account. ...
    (comp.security.ssh)
  • Old 4.2 user, with 6.2 newbie questions
    ... I have a shell account on my isp which runs 4.10-STABLE. ... I use my own sendmail to send mail out to various lists on ... retrieve mail on my isp via fetchmail. ...
    (freebsd-questions)
  • Re: Backgrounding a stream, and sendmail?
    ... >> just redirect the output to a file instead of sendmail.) ... > shell command like ... when prog_b has it's stdout redirected nothing ... > is done instead of printing to stdout you could start sendmail from within ...
    (comp.os.linux.development.apps)
  • Re: Backgrounding a stream, and sendmail?
    ... > but that doesn't work at all, even if I just redirect ... > the output to a file instead of sendmail.) ... The shell won't restart prog_c for you, ... did was connecting stdout of prog_b to the stdin of prog_c ...
    (comp.os.linux.development.apps)