Re: chroot email + browser ???



Menno Duursma <menno@xxxxxxxxxxx> (06-02-26 09:13:38):

nobody@xxxxxxx (Kevin the Drummer) (06-02-24 16:17:09):

[ Mail and Web apps under different users. ]

That's a verbatim copy of the email address from the "From" header in
the OP's post. Not my fault.


Then allow your main user to use sudo without a password. Remember
to still give the different accounts different passwords, otherwise
you have no gain in security.

No. The useradd command defaults to something like * or !! in the
password field of the /etc/shadow file (if it doesn't: change it to
that by hand) which *disables* password login to that account
altogether, you can still 'su' to it though. But if you use 'sudo'
anyways you can do better still and set the shell of the user to
/bin/false (use like 'sudo -s -u <user>' for testing wat the user can
do - if needed.)

On my box, sudo denies access to accounts without a password or valid
shell. I'd set some random password for this kind of account.


Regards.
.



Relevant Pages

  • Re: Recovery via Unrecovery
    ... off our YQNC project manager. ... 467 accounts loaded with empty shell fields. ... notoriously cranky math professor whose latest reason to be pissed off ...
    (alt.sysadmin.recovery)
  • Re: alice
    ... > regarding your server alice. ... Yes, we offer accounts, shell access and vnc access to X11, web space, ... language I am developing), etc. ...
    (Debian-User)
  • Re: Unix Application,
    ... We have found this to not be the case, and get tons of requests for non-expiring passwd's from various groups that lack a clue as to what a shell might be, and any clue at all about maintianing their accounts. ... Are you using SPI, Watchfire or WhiteHat? ...
    (Pen-Test)
  • Re: How do I disable shell access but allow FTP and E-mail?
    ... I want to create seperate user accounts for Shell access ... > accounts for unencrypted activities (FTP and E-mail) and a seperate ... It's a remotely hosted dedicated server, ...
    (comp.os.linux.security)
  • Re: I need Ideas on securing a remote Win2k machine
    ... Hi Dirk, ... I would probably setup that application as their shell, ... > to that machine, so that only domain accounts I "grant" access to, can ... > account access to a special shell - while the main admin accounts ...
    (microsoft.public.win2000.security)