Re: User?s and Shells

From: Devdas Bhagat (dvb@users.sourceforge.net)
Date: 12/21/02

  • Next message: Adam H. Pendleton: "Re: User?s and Shells"
    Date: Sat, 21 Dec 2002 22:55:25 +0530
    From: Devdas Bhagat <dvb@users.sourceforge.net>
    To: Brian Hatch <focus-linux@ifokr.org>, "'focus-linux@securityfocus.com'" <focus-linux@securityfocus.com>
    
    

    On 20/12/02 22:52 +0100, Christian Hammers wrote:
    <snip>
    > I'm wondering why I would want that - until now nobody could give me a
    > good argument although everybody learns to remove the shells :-(
    >
    > * If I give my users a disabled password, they cannot¹ login via passwd
    > based ssh/ftp/pop3 etc.
    Keys. ssh-keygen.

    > * But, on the other hand, I can have a
    > su news -c /usr/local/script_running_as_user_news.sh
    su - news -s /bin/sh -c "/path/to/script taking arguments"

    > Any hints?
    Administrators have to close all holes, crackers need just one.
    Why leave something that might be misused?
    After all, hardening a box involves restricting what can be done by what
    users.

    Devdas Bhagat



    Relevant Pages

    • Re: i ride facing traffic--comments please
      ... nobody knows you're a jerk. ... If I had been walking my bike in the crosswalk, ... Bicycling the wrong way is just plain wrong, ...
      (rec.bicycles.tech)
    • Re: Book-able view of ID as speculative science
      ... >Nobody has seen it perform major changes to actual organisms. ... "But MU is empty". ...
      (talk.origins)
    • Re: i ride facing traffic--comments please
      ... nobody knows you're a jerk. ... My most important bike safety rule is, never assume a car sees you. ... If I had been walking my bike in the crosswalk, ...
      (rec.bicycles.tech)
    • Re: Bogus NullPointerExceptions
      ... Nobody has been appointed any kind of gatekeeper, bouncer, or whatever ... [snip threats that you'll continue attacking me if I don't stop ...
      (comp.lang.java.programmer)
    • Re: Lost five dimes today on Akron
      ... dealing with. ... Nobody knows who you really are or even wants to know. ... based on your fantasy football team, based on how you claim to be the object ...
      (rec.gambling.sports)