User Tools

Site Tools


wiki:security:rbash

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
Last revision Both sides next revision
wiki:security:rbash [2014/11/01 09:24]
woglinde [rbash short feature overview]
wiki:security:rbash [2014/11/01 12:02]
woglinde
Line 9: Line 9:
 and hard to setup correctly. Another option is the use of rbash, but with the current state of x2go-server there and hard to setup correctly. Another option is the use of rbash, but with the current state of x2go-server there
 are serval steps so setup it up working correctly. are serval steps so setup it up working correctly.
 +
 +This guide is focused on a single application approach, no audio, remote/mounted dirs and printing are involved.
  
 ====== rbash short feature overview ====== ====== rbash short feature overview ======
Line 93: Line 95:
 </code> </code>
  
 +===== Security concerns =====
 +There could be still problems to brake out of rbash, no one yet made a security audit of the linked x2go scripts, if they allow the execution of a real shell
 +via options.
 ====== rbash as default shell (optional)====== ====== rbash as default shell (optional)======
  
Line 98: Line 103:
 to be fixed too. to be fixed too.
  
 +In
 +<code bash>
 +/usr/sbin/x2gocleansessions 
 +</code>
  
 +the lines with
 +
 +<code bash>
 +system("su", "@sinfo[11]", "-c"
 +</code>
 +
 +needs to be changed to
 +
 +<code bash>
 +system("su", "@sinfo[11]", "-s", "/bin/bash", "-c",
 +</code>
wiki/security/rbash.txt ยท Last modified: 2014/11/03 13:07 by woglinde