Re: Restricted Shells or Menu Based Shells

From: Seth Arnold (sarnold@wirex.com)
Date: 03/08/02


Date: Fri, 8 Mar 2002 10:06:40 -0800
From: Seth Arnold <sarnold@wirex.com>
To: focus-linux@securityfocus.com


On Thu, Mar 07, 2002 at 10:31:37AM -0000, Brian Clifton wrote:
> Even if a user could do this, wouldn't disabling anonymous FTP be a
> simple answer or am I missing something?

The problem isn't accepting ftp connections -- it is allowing users to
use the ftp client on the machine with the 'restricted shell' -- because
the ftp client allows users to execute programs locally pretty easy. Of
course, you have the source to your ftp clients, so feel free to modify
your client of choice to prevent that. :)

Of course, many unix programs have this ability, because it is useful.
Practically every editor, every MUA, every terminal-based web browser,
and other useful programs, all have easy access to the shell. Many
programs have 'restricted' modes that are supposed to prevent access to
the shell, but mistakes happen.

Ever wonder what happens if a user sets EDITOR=/bin/sh before editing
outgoing email? I never thought about it until today. I wonder what
happens. And perhaps someone trying to create a restricted shell
probably ought to wonder about it too. :)

-- 
UniNet InfoSec Conference   April 15-19   http://infosec.uninet.edu 




Relevant Pages

  • Re: FTP strangeness
    ... Listing an empty existing directory shouldn't return an error code. ... servers cannot issue a 550 reply to a LIST command. ... As demonstrated more than just VMS ftp servers do the latter - for situations ... In any case an FTP client should comply with the robustness principle of RFC ...
    (comp.os.vms)
  • Re: hmt will not load in FTP client after proxy server problems.
    ... Now as per the FTP issue. ... the free FTP client FileZilla: ... off the server, and upload new ones. ... index.htm file and the index_files folder that contain the supporting ...
    (microsoft.public.publisher.webdesign)
  • RE: FreeBSD telnetd and Microsoft Internet Explorer
    ... >Subject: Re: FreeBSD telnetd and Microsoft Internet Explorer ... >> Hitting them with IE 6.0.2800.1106 ftp client I ... >> FTP client being bad. ... >other clients) it crashes. ...
    (freebsd-questions)
  • Re: FreeBSD telnetd and Microsoft Internet Explorer
    ... > Hitting them with IE 6.0.2800.1106 ftp client I ... > FTP client being bad. ... > on a 6.0 FreeBSD server. ... other clients) it crashes. ...
    (freebsd-questions)
  • Re: How to make ftp server less verbose
    ... > modem-equipped devices to our FTP server and we found that FTP protocol ... suspect the response messages as being a significant portion of that. ... writing a relatively simple proxy in front of the FTP server? ... you'll need to pass on faithfully to the FTP client is the 227 response from ...
    (microsoft.public.inetserver.iis.ftp)