08-05-2009
Since the users have access to the server as root, there's little you can do. The only thing I can think of is creating an encrypted volume that is mounted only on-demand. But during that time it's just as accessible as everything else.
By the way, when the higher-ups decided to share the root password, did they think of a way how to discover the person responsible in case something bad happens? rm -rf is a quick, yet deadly command...
10 More Discussions You Might Find Interesting
1. Cybersecurity
restricted access...
Hi
I need to restrict users shell access to only $HOME under /home for each user. I don't want them getting out of their own directories. From what I understand chroot is something I could use, but I want to avoid this since it involves creating symbolic links to a number... (9 Replies)
Discussion started by: alwayslearningunix
9 Replies
2. UNIX for Dummies Questions & Answers
I need to create a user that only has access to 1 directory (e.g. /vol/mita/test). The user needs to be able to rsh into that directory to run a script. The user should not be able to navigate to any other directories above /vol/mita/test. Any help would be appreciated! (4 Replies)
Discussion started by: ngagne
4 Replies
3. UNIX for Dummies Questions & Answers
I have a need to allow only certain IP addresses to access a machine running solaris 9. I am not sure how this can be accomplished.
Thanks in advance for your help.
Patch (2 Replies)
Discussion started by: patch
2 Replies
4. Solaris
Hi All,
I'm on Solaris 8, I need to provide Read-only access to a user to 2 directories only.
Using rsh (restricted shell) as the user's login shell, I can restrict the user's access to a certain directory only, but how can I set in such a way that the user can access only the 2 directories... (4 Replies)
Discussion started by: max_min
4 Replies
5. UNIX for Advanced & Expert Users
I'm the admin in a shop in which my developers have and use the root account, all UNIX newbies.
I've been unable to convince management myself that this is an unacceptable practice.
I've looked in a couple books I have and can't find any chapters, discussions, etc that make the argument that... (2 Replies)
Discussion started by: keith.m
2 Replies
6. Solaris
We want to secure access to a server by restricting the number of users who can login to it. Our users are NIS users. Only few of them can telnet/ssh this server.
Do you have any idea on how to implement that?
thanks. (1 Reply)
Discussion started by: melanie_pfefer
1 Replies
7. UNIX for Dummies Questions & Answers
Hi all,
I have user called "Z". The home directory is /home/Z. I have another directory /home/Z/OP. Within /home/Z/OP, i have 2 directories
/home/Z/OP/OP1 and /home/Z/OP2.
I want to restrict access for Z to only access
/home/Z/OP and
/home/Z/OP1 and
/home/Z/OP2.
What kind of... (4 Replies)
Discussion started by: new2ss
4 Replies
8. Solaris
Dear All,
I have created a user called "x" who is allowed only to FTP and it is working fine. Here my problem is, I want to give access to a particular directory say for eg:- /dump/test directory. I don't find any option in the useradd command to restrict access to this particular directory only... (1 Reply)
Discussion started by: Vijayakumarpc
1 Replies
9. Solaris
Hi all.
I've had a quick look around but cant see anything exactly matching my requirements.
I have a new T2000 running S10. Im looking to restrict the no. cores that a S10 non-global zone can use to 1 only. The box is single CPU but 8core.
I want to do this to save on some software... (4 Replies)
Discussion started by: boneyard
4 Replies
10. UNIX for Dummies Questions & Answers
Hello,
I am using MySecureShell to chroot all sftp accesses. The problem that I have is that my boss does not want root to be able to use sftp. Root should still be able to ssh. Any ideas? (2 Replies)
Discussion started by: mojoman
2 Replies
LEARN ABOUT DEBIAN
d_passwd
d_passwd(4) File Formats d_passwd(4)
NAME
d_passwd - dial-up password file
SYNOPSIS
/etc/d_passwd
DESCRIPTION
A dial-up password is an additional password required of users who access the computer through a modem or dial-up port. The correct pass-
word must be entered before the user is granted access to the computer.
d_passwd is an ASCII file which contains a list of executable programs (typically shells) that require a dial-up password and the associ-
ated encrypted passwords. When a user attempts to log in on any of the ports listed in the dialups file (see dialups(4)), the login program
looks at the user's login entry stored in the passwd file (see passwd(4)), and compares the login shell field to the entries in d_passwd.
These entries determine whether the user will be required to supply a dial-up password.
Each entry in d_passwd is a single line of the form:
login-shell:password:
where
login-shell The name of the login program that will require an additional dial-up password.
password An encrypted password. Users accessing the computer through a dial-up port or modem using login-shell will be required to
enter this password before gaining access to the computer.
d_passwd should be owned by the root user and the root group. The file should have read and write permissions for the owner (root) only.
If the user's login program in the passwd file is not found in d_passwd or if the login shell field in passwd is empty, the user must sup-
ply the default password. The default password is the entry for /usr/bin/sh. If d_passwd has no entry for /usr/bin/sh, then those users
whose login shell field in passwd is empty or does not match any entry in d_passwd will not be prompted for a dial-up password.
Dial-up logins are disabled if d_passwd has only the following entry:
/usr/bin/sh:*:
EXAMPLES
Example 1: Sample d_passwd file.
Here is a sample d_passwd file:
/usr/lib/uucp/uucico:q.mJzTnu8icF0:
/usr/bin/csh:6k/7KCFRPNVXg:
/usr/bin/ksh:9df/FDf.4jkRt:
/usr/bin/sh:41FuGVzGcDJlw:
Generating An Encrypted Password
The passwd (see passwd(1)) utility can be used to generate the encrypted password for each login program. passwd generates encrypted pass-
words for users and places the password in the shadow (see shadow(4)) file. Passwords for the d_passwd file will need to be generated by
first adding a temporary user id using useradd (see useradd(1M)), and then using passwd(1) to generate the desired password in the shadow
file. Once the encrypted version of the password has been created, it can be copied to the d_passwd file.
For example:
1.
Type useradd tempuser and press Return. This creates a user named tempuser.
2. Type passwd tempuser and press Return. This creates an encrypted password for tempuser and places it in the shadow file.
3. Find the entry for tempuser in the shadow file and copy the encrypted password to the desired entry in the d_passwd file.
4. Type userdel tempuser and press Return to delete tempuser.
These steps must be executed as the root user.
FILES
/etc/d_passwd dial-up password file
/etc/dialups list of dial-up ports requiring dial-up passwords
/etc/passwd password file
/etc/shadow shadow password file
SEE ALSO
passwd(1), useradd(1M), dialups(4), passwd(4), shadow(4)
WARNINGS
When creating a new dial-up password, be sure to remain logged in on at least one terminal while testing the new password. This ensures
that there is an available terminal from which you can correct any mistakes that were made when the new password was added.
SunOS 5.10 2 Sep 2004 d_passwd(4)