The UNIX and Linux Forums  

Go Back   The UNIX and Linux Forums > OS Specific Forums > SUN Solaris
Google UNIX.COM


SUN Solaris The Solaris Operating System, usually known simply as Solaris, is a free Unix-based operating system introduced by Sun Microsystems .

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
need to restrict user to his home dir lidram SUN Solaris 5 02-06-2008 07:03 AM
How to restrict the number of commands user can execute rockysfr Shell Programming and Scripting 1 07-03-2007 10:53 AM
how to restrict the perticular commands to users krishna176 SUN Solaris 0 03-24-2007 09:26 AM
Possible to restrict SED braindrain Shell Programming and Scripting 7 12-12-2006 09:03 AM
How to restrict account to one log-in? Egroman UNIX for Dummies Questions & Answers 0 09-02-2004 12:59 AM

Reply
 
Submit Tools LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 05-11-2008
Registered User
 

Join Date: Jul 2007
Posts: 38
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
Question restrict commands

Dears,
how to determine the commands that could be used by certain user..like I want to prevent some users from running pwd command????

Thanx
Reply With Quote
Forum Sponsor
  #2 (permalink)  
Old 05-11-2008
Registered User
 

Join Date: Dec 2007
Location: Paris
Posts: 241
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
pwd being a shell builtin, you'll have a hard time disabling it outside patching the shell itself or building your own limited one.
Reply With Quote
  #3 (permalink)  
Old 05-11-2008
Registered User
 

Join Date: Jul 2007
Posts: 38
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
Question

I dont know how to patch the shell ?? is there any other way???
Reply With Quote
  #4 (permalink)  
Old 05-11-2008
robotronic's Avatar
Can I play with madness?
 

Join Date: Apr 2002
Location: Italy
Posts: 369
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
Maybe you can fool your users inserting in their environment these custom functions:

builtin() { echo "builtin is disabled"; }
unset() { echo "unset is disabled"; }
pwd() { echo "pwd is disabled"; }

For now I don't have any clever ideas
Reply With Quote
  #5 (permalink)  
Old 05-11-2008
Registered User
 

Join Date: Dec 2007
Location: Paris
Posts: 241
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit! Stumble this Post!Spurl this Post!
I guess the right solution is using an existing restricted shell (eg: rksh). I was just pointing "pwd" isn't a command easy to neutralize. robotronic functions should work though along with rksh which forbids the user to run the "cd" command, something certainly more useful than forbidding "pwd".

"man rksh" for details.
Reply With Quote
Google UNIX.COM
Reply

Thread Tools
Display Modes


The 50 most popular UNIX and Linux searches.
Google Search Cloud for The UNIX and Linux Forums
421 service not available, remote server has closed connection ^m automate ftp autosys awk trim bash eval bash exec bash for loop command copy/move folder in unix couldn't set locale correctly curses.h cut command in unix export command in unix find grep find mtime find null character in a unix file grep multiple lines grep or grep recursive hp-ux ifconfig inaddr_any inappropriate ioctl for device lynx javascript mailx attachment mget mtime ping port remove first character from string in k shell replace space by comma , perl script scp recursive segmentation fault(coredump) sftp script snoop unix stale nfs file handle syn_sent tar exclude tar extract to folder test: argument expected unix unix .profile unix forum unix forums unix internals unix interview questions unix mtime unix simulator unix.com vi substitute vi+substitute+end+of+line+character while loop within while loop shell script


All times are GMT -7. The time now is 04:07 AM.


Powered by: vBulletin, Copyright ©2000 - 2006, Jelsoft Enterprises Limited.
The UNIX and Linux Forums Content Copyright ©1993-2008 The CEP Blog All Rights Reserved -Ad Management by RedTyger Visit The Global Fact Book

Content Relevant URLs by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101