For cron you could look into cron.(allow|deny), access to wall could be allowed tru sudo when you chop off the world rx bits.
*Since you're serving out shells and you found out tru a mild incident ppl can't always be trusted, Id like to suggest you look into a kernelpatch called GRSecurity (grsecurity.net). Read up on what it offers and if that suits you in helping cope with shell users.
|