Best way for a restricted shell account

Best way for a restricted shell account

Post by Marc Bigle » Wed, 16 May 2001 02:02:46



Hello,

I would like to have your opinion on what is the best way to handle a
restricted login shell. Basically I will have a user which will only
need to run some postgresql commands (database exports/imports). Is
there any restricted shell available (like rksh on Solaris) or do you
see anyother ideas on how to protect my system at the maximum.

Thanks

Regards,
Marc

 
 
 

Best way for a restricted shell account

Post by jose » Wed, 16 May 2001 02:47:40



> I would like to have your opinion on what is the best way to handle a
> restricted login shell. Basically I will have a user which will only
> need to run some postgresql commands (database exports/imports). Is
> there any restricted shell available (like rksh on Solaris) or do you
> see anyother ideas on how to protect my system at the maximum.

rbash (you may need to recompile it) is a good restricted shell for
people. it may meet your needs ...



 
 
 

Best way for a restricted shell account

Post by Alfred Breu » Wed, 16 May 2001 15:27:46



>Is there any restricted shell available (like rksh on Solaris)

/bin/rksh ?
also, you might want to add /bin/rksh to /etc/shells.
 
 
 

Best way for a restricted shell account

Post by Peter Str?mbe » Wed, 16 May 2001 20:14:49



> I would like to have your opinion on what is the best way to handle a
> restricted login shell. Basically I will have a user which will only
> need to run some postgresql commands (database exports/imports). Is
> there any restricted shell available (like rksh on Solaris) or do you
> see anyother ideas on how to protect my system at the maximum.

"restricted shell" is trivial to break out of.
To "protect my system at the maximum" use a carefully setup chrooted
environment.

--
Peter Str?mberg

 
 
 

Best way for a restricted shell account

Post by Marc Bigle » Thu, 17 May 2001 05:17:27


Quote:> "restricted shell" is trivial to break out of.
> To "protect my system at the maximum" use a carefully setup chrooted
> environment.

Do you have an example how to do a chrooted environement ?

Regards,
Marc

 
 
 

1. Restricted Shell Account

Anyone out there know anything about setting up user accounts with
restricted shells? I know you have to create or modify the account to use
/usr/lib/rsh as the shell. Where I get hazy is setting up the /usr/rbin
directory. The only references I can find say to create the directory, then
copy or link the commands to it that you want to restrict the user to. OK,
this is a dumb question, but how do you do that? I know how to copy and
link files to a directory, but commands? I just don't quite get it. Any
help would be GREATLY appreciated.

Thanks,
        John

2. agpgart changes for 2.5.26

3. Temporary restricted shell accounts: howto

4. 12"1 TFT LCD and Modeline

5. HELP: DAT should be useable by specific account (restricted shell, etc)

6. Important:Savage4 VIDEO CARD PROBLEMS

7. Restricted (or Captive) Account/Shell

8. page frame number ?

9. Restricted Bash Shell Accounts

10. Alternative editors to vi (for restricted shell accounts)

11. restricting users with shell accounts

12. What's Best: Shell or PPP Accounts for Internet Access ?

13. Best shell for disabled account