[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Limiting User Commands



On Mon, 8 Nov 2004 09:28:10 -0900, Christopher Swingley
<cswingle@iarc.uaf.edu> wrote:
> Make symbolic links between allowed commands and '/usr/local/rbin'
> 
> As I said before, this is just a simple attempt to reduce priviledge.
> There are undoubtably ways around it, some easier than others depending
> on what's in /usr/local/rbin.

This won't prevent users from executing banned commands with Perl
scripts called by Apache. I'm opposed to using rbash for this reason
and because some users might want to use a non-bash shell.

-Stephen Le



Reply to: