[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: disable ssh/login for individual an account?



* patrick denton <patrick.denton@dataops.net> [001116 05:57]:
> I'm using an account called (renamed to protect the innocent) "fwadmin"
> which only has permissions by way of sudo to vi /etc/ipf.rules, vi
> /etc/ipnat and execute ipf, ipnat, ipmon and ipfstat.

Patrick, don't forget that vi(1) can be used to execute commands as
well. Ensure to be requiring the use of the -S flag (perhaps through a
small C program that will vi the correct files).

-- 
``Oh Lord; Ooh you are so big; So absolutely huge; Gosh we're all really
impressed down here, I can tell you.''