LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Closed Thread
  Search this Thread
Old 09-30-2011, 12:41 AM   #1
m.sabouri
LQ Newbie
 
Registered: Aug 2011
Posts: 3

Rep: Reputation: Disabled
safe user permissions


I want to give about 30 users to some people I don't trust at all on my server . I want them to be able to use their account with SSH for tunneling . They must not be able to see what's going on inside the server or executing commands . I thought of "chmod o-xr -R /" but I think It's not a good option, since other programs must be able to see somethings . any suggestions ? I saw something like "bash=/bin/null" somewhere a long time ago but I don't remember what was it and can't find it anymore
 
Old 09-30-2011, 04:26 AM   #2
jv2112
Member
 
Registered: Jan 2009
Location: New England
Distribution: Arch Linux
Posts: 719

Rep: Reputation: 106Reputation: 106
Partition the server so the needed directories have access permission but all else is denied.

 
Old 09-30-2011, 07:33 AM   #3
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Rep: Reputation: 78
need clarity on what you mean by "ssh tunneling". do you mean tunneling of applications, or just the ssh session is "tunneled" because its encrypted? what exactly do you mean by "they must not be abole to see what going on inside the server"? they cant run top or vmstat ?? if the system is in good perms shape then there shouldnt be a issue, etc. do you run SElinux?

no need to get overly complicated.

create groups, allow only those groups to ssh (lock down ssh via sshd_config, etc).
then configure sudo to allow those groups to do certain things, etc.
i chmod 700 su so only my sysadmins can sudo su, etc.
 
Old 09-30-2011, 08:09 AM   #4
m.sabouri
LQ Newbie
 
Registered: Aug 2011
Posts: 3

Original Poster
Rep: Reputation: Disabled
many internet websites are filtered in Iran and we can't visit them . we used VPNs ( PPTP, IPSec, etc ) to access internet of offshore servers, but now even VPN ports are blocked . ssh is seeming very nice now, this command "ssh -D 1234 -C user@myserver" and setting system proxy to 127.0.0.1:1234 allows me to surf the web now, but giving away user accounts to others is not a good idea . some issues here are disk space, bandwidth and security problems . I set other users default bash to this script :

#!/bin/sh
read -p "Some prompt"
exit

so now people can't use bash, but I'm not sure if It's enough to avoid disasters . I want them to be able to use tunneling only, nothing else

sorry for my poor English, I just can't find words to describe my problem
 
Old 09-30-2011, 08:20 AM   #5
Noway2
Senior Member
 
Registered: Jul 2007
Distribution: Gentoo
Posts: 2,125

Rep: Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781Reputation: 781
Quote:
many internet websites are filtered in Iran and we can't visit them . we used VPNs ( PPTP, IPSec, etc ) to access internet of offshore servers, but now even VPN ports are blocked
Unfortunately, this topic goes against rule 14 in that it is a topic that can be damaging to LQ's reputation. Regardless of how sympathetic we may be to your cause, topics involving circumventing government restrictions are not permitted. This thread has been reported to the moderators.
 
Old 09-30-2011, 12:41 PM   #6
Linux_Kidd
Member
 
Registered: Jan 2006
Location: USA
Posts: 737

Rep: Reputation: 78
i dunno legal aspect of the question, but shell /bin/false and ssh -N should do it.
 
Old 10-01-2011, 05:24 AM   #7
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Nsflq

Quote:
Originally Posted by Linux_Kidd View Post
i dunno legal aspect of the question
...then you best find out before posting, right?


As stated by Noway2 circumvention of access restrictions in the broadest meaning of the word is not a topic suitable for LQ. This thread is closed.
 
  


Closed Thread



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] filesystem permissions question - making so user can't change permissions? c0pe Linux - Security 4 07-12-2010 09:06 AM
Is it safe to give apache permissions? Karas Linux - Newbie 5 10-16-2009 09:54 AM
Safe to kill all user: 'nobody' processes? lagu2653 Linux - Security 4 11-06-2005 06:28 PM
Which user accts in Redhat safe to delete? scottjwoodford Linux - Security 5 06-11-2005 10:21 AM
Is it safe to delete default nobody user? dunkyb Linux - General 2 03-16-2003 12:38 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:44 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration