Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <Pine.LNX.4.58.0402041753290.611@coyote.op5.se>
Date: Wed, 4 Feb 2004 18:00:45 +0100 (CET)
From: Andreas Ericsson <exon@....se>
To: owl-users@...ts.openwall.com
Subject: Re: dhcp client

I don't think that's a very good solution, considering system process
pseudo-users should have /bin/false as their shell.
If any of those pseudo-users need to run a shell command, execution would
fail. If the check is only performed when an interactive shell is spawned
it might be useful, but then it could be bypassed by 'unexpected' actions
(which is what to expect from script kiddies).

Mvh / Best Regards
Andreas Ericsson / Sourcerer
OP5 AB
+46 (0)733 709032
andreas.ericsson@....se

On Wed, 4 Feb 2004, Berend-Jan Wever wrote:
>
> PS. I modified my "/bin/sh" to only run when the user executing it doesn't
> have "/bin/false" as shell in "/etc/passwd". It's a lame security trick
> that's easily bypassed, but it does keep the script kiddies out. Maybe it's
> something Owl could use ?
>

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.