Re: How to log all commands?

From: Nekromancer (foo_at_bar.org)
Date: 05/31/05

  • Next message: Nekromancer: "Re: How to log all commands?"
    Date: 30 May 2005 22:07:08 GMT
    
    

    Dragan Cvetkovic <me@privacy.net> wrote in
    news:lmekboebq0.fsf@privacy.net:

    > If they can execute nmap (OP's example), why should they not be able
    > to run other programs?
    >

    I'm really sorry I can't be more specific, because that would have helped
    to avoid discussion.
    The users will be able to run several potentially dangerous tools (like
    nmap), but NOTHING ELSE. Not in that box, at least.
    The output of the tools will be automatically transferred as inocuos .txt
    files to the office environment for processing.
    The main point is that in the "front" of dangerous machines restriction
    will be heavy, and I want the logs of all commands.
    It's highly unlikely (well, it'll be forbidden) that the users will be able
    to use powerful editors like vi (that has built-in command execution), gcc,
    etc. Everything under their directories will be 100% noexec. root will be
    heavily restricted via LIDS.

    I can avoid the use of other shells by having only bash, if required.

    PROBABLY (still under discussion) I'll implement the commands using sudo,
    to have logging on that side at least.

    Cheers,

    Mike


  • Next message: Nekromancer: "Re: How to log all commands?"

    Relevant Pages

    • Re: Common Procedure
      ... A common procedure is great idea. ... Further, I would avoid using "domenuItem", as that suggests a particular ... You standard code module can thus be: ... try and stay away from those old style menu commands. ...
      (microsoft.public.access.formscoding)
    • Re: Odd VFP DO WHILE Behavior
      ... NULL is almost impossible to avoid. ... in commands expecting logical walue like WHILE DO or FOR ENDFOR is ... The loop code is not executed, which is what I would expect. ... The loop code is executed forever. ...
      (microsoft.public.fox.vfp.forms)
    • Re: Slightly OT: DVD players
      ... as slow to respond to commands as its predecessor and noisy in ... (so that I can avoid it!) ...
      (uk.tech.digital-tv)
    • Re: Slightly OT: DVD players
      ... as slow to respond to commands as its predecessor and noisy in ... (so that I can avoid it!) ...
      (uk.tech.digital-tv)
    • Re: How to create a Recommended Reading list?
      ... option that you wanted to avoid, and instead of typing all the \nocite ... unwanted lines and use "change" commands to convert the bibtex entries ...
      (comp.text.tex)