LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-05-2003, 07:44 AM   #1
azi
LQ Newbie
 
Registered: Nov 2003
Posts: 17

Rep: Reputation: 0
X aplications


Hi all,..


I run a server with shell accounts and I noticed that any user can run X aplications (such as !!!!startkde!!!!,xchat,gftp,..etc) from his home...So, the question is : How can I block runing X aplications


Realy sory for my eanglish :/
 
Old 11-05-2003, 10:46 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Did you harden the box? If not that's what you should start with. Check out the LQ FAQ: Security references, post #1 under "Checklists", "Securing", "Hardening, distro specific" and "Log analysis tools, resources".

I run a server with shell accounts and I noticed that any user can run X aplications (..) from his home
A shell server is a shell server and not a toybox. It shouldn't run X at all. You need to minimise chances people abuse applications by minimising the amount of applications installed. This means essentially all applications not necessary for the function of the box should be removed or protected (removal is better). If that's impossible you will need to 1. take away access rights for "world" on all dirs, configs, libs, binaries and other resources involved, 2. chown 'em to a separate group, 3. remove /usr/X11 from these users $PATH and 4. Install the Grsecurity kernel patch. It includes TPE (Trusted Path Execution) which means users will have no chance executing apps outside of the path *you* specify, options for denying users client and/or server socket operations, process and memory protection and ACL's for even more strict access definitions.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
running X aplications in XP jpoot Red Hat 4 11-16-2005 12:01 AM
Newbie wants to install aplications confusedpenguin Linux - Newbie 2 03-15-2005 08:47 AM
Mandrake 10 - unwanted aplications at startup zionz Mandriva 6 09-01-2004 04:06 AM
How do i install the other aplications ? sending_to_god Linux - Software 1 06-27-2004 04:13 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:27 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration