Openwall Project   /home  Owl  JtR  Pro  crypt  pam_passwdqc  tcb  phpass  scanlogd  popa3d  msulogin  /  Linux  BIND  /  advisories  presentations  /  services  donations  /  wordlists  passwords  /  news  community  lists  wiki  CVSweb  mirrors  signatures
bringing security into open environments
 
Password Recovery Resources on the Net
[<prev] [next>] [<thread-prev] [month] [year] [list]
Date: Wed, 4 Feb 2004 18:00:45 +0100 (CET)
From: Andreas Ericsson <exon@....se>
To: owl-users@...ts.openwall.com
Subject: Re: dhcp client

I don't think that's a very good solution, considering system process
pseudo-users should have /bin/false as their shell.
If any of those pseudo-users need to run a shell command, execution would
fail. If the check is only performed when an interactive shell is spawned
it might be useful, but then it could be bypassed by 'unexpected' actions
(which is what to expect from script kiddies).

Mvh / Best Regards
Andreas Ericsson / Sourcerer
OP5 AB
+46 (0)733 709032
andreas.ericsson@....se

On Wed, 4 Feb 2004, Berend-Jan Wever wrote:
>
> PS. I modified my "/bin/sh" to only run when the user executing it doesn't
> have "/bin/false" as shell in "/etc/passwd". It's a lame security trick
> that's easily bypassed, but it does keep the script kiddies out. Maybe it's
> something Owl could use ?
>

Hosted by DataForce ISP - Powered by Openwall GNU/*/Linux