05-19-2016
You could try a number of tweaks, such as:-
- On login, set the command history file to one based on the connecting IP address
- Collect all commands issued by a tty session and write them to the syslog, including the connecting IP address
- Intercept the kill command with a script that logs the process id and details of the process before calling the real kill command
- Some other variation?
Of course, all of these can bypassed, but they might give you a clue if someone forgets. The best method is to set up separate accounts for each user so that they cannot do this in the first place. You are exposing yourself to untold horrors from mistakes and malicious attack.
Is there a good reason for not having separate user accounts, or is it just 'easy'. Remember that security is like contraception - people may not like it but the cost of mistakes can be enormous.
I hope that the above suggestions may help,
Robin
10 More Discussions You Might Find Interesting
1. Shell Programming and Scripting
Hi,
I want to execute a script - of different user from my script.
I have tried the su command
su - username -c "scriptname"
it works but asked for password.
Is there any way for supplying the password to it thru script, not interactively.
Or is there any other way to achieve the... (5 Replies)
Discussion started by: yeheyaansari
5 Replies
2. UNIX for Dummies Questions & Answers
How do i in a script determine the user that is executing it? (2 Replies)
Discussion started by: Chiefos
2 Replies
3. UNIX for Dummies Questions & Answers
Hi,
I need to execute the following unix command through my java code -
zip -e
When i execute this command from the command prompt, i am prompted for a password in the following manner -
Enter password:
Verify password:
Is it possible to provide the password inthe first command itself... (5 Replies)
Discussion started by: jacob23
5 Replies
4. UNIX for Dummies Questions & Answers
I have two machines, one running Windows and another one Unix over a network. I want to execute a batch file on the Windows machine using a script running on the Unix machine.
I have tried creating a rsa key and transferrring it to the destination machine but it doesn't work. The purpose was to... (3 Replies)
Discussion started by: MobileUser
3 Replies
5. UNIX for Dummies Questions & Answers
When trying to find a list of files with specific text in them using
find . -type f -exec grep -l "DataStage Job 4263" {}\;
I get error
find: missing argument to 'exec'
How can I correct this ? I'm on Linux Red Hat.
Cheers
PS I'm a DataStage programmer not a systems support... (4 Replies)
Discussion started by: jackdaw_at_work
4 Replies
6. UNIX for Advanced & Expert Users
Hi all,
Just need some help the following scenario,
Is there any UNIX command to find the unix machine type (like whether the machine is belongs to Ssun ultra 45 type) like that .. please help me (2 Replies)
Discussion started by: abhisheksunkari
2 Replies
7. Shell Programming and Scripting
Hi All,
i have two machines like x and y . my requirement is i should connect to machine Y from x through ssh connection . and do some operation such as copy and move and delete files in Y machine .
i tried with this code but it is doing in machine x only . and i need to exit from Y when... (1 Reply)
Discussion started by: rateeshkumar
1 Replies
8. UNIX for Dummies Questions & Answers
Buddies, I am trying to copy the file 'xcopyq' from /home/sandip to /home/sandip/testdir using the below command and getting the error as shown below:-
sandip@manu:~$ find /home/sandip -type f -name '*xcopyq*' -exec cp{} /home/sandip/testdir/ \:
find: missing argument to `-exec'
Am I... (2 Replies)
Discussion started by: sandip250382
2 Replies
9. Shell Programming and Scripting
Running below command , but unable to print the filename , is there way to print filename/dirname using -print option
find . -type f -exec aclput -i fileacl.template {} \; (5 Replies)
Discussion started by: lalitpct
5 Replies
10. UNIX for Dummies Questions & Answers
hi
how to restrict a user ro run rm command.
In this scenario we have a user/group has below in sudoers
user ALL=(ALL) ALLis there a way to restrict the user from just executing rm command (9 Replies)
Discussion started by: robo
9 Replies
KILL(1) General Commands Manual KILL(1)
NAME
kill, broke - print commands to kill processes
SYNOPSIS
kill name
broke
DESCRIPTION
Kill prints commands that will cause all processes called name and owned by the current user to be terminated. Use the send command of
81/2(1), or pipe the output of kill into rc(1) to execute the commands.
Kill suggests sending a kill note to the process; the same message delivered to the process's ctl file (see proc(3)) is a surer, if heavy
handed, kill, but is necessary if the offending process is ignoring notes.
Broke prints commands that will cause all processes in the Broken state and owned by the current user to go away. When a process dies
because of an error caught by the system, it may linger in the Broken state to allow examination with a debugger. Executing the commands
printed by broke lets the system reclaim the resources used by the broken processes.
SOURCE
/rc/bin/kill
/rc/bin/broke
SEE ALSO
ps(1), stop(1), proc(3)
KILL(1)