Re: Security
Posted in 1992
If a program supports escaping to the shell, then *it* must set things up to fork the child process. It is by convention only that it uses the contents of $SHELL as the program that controls the process. We have a number of users who log into ID's that are "locked into" menu systems here also. When the top-level menu is exited, the user is logged out. Under SunOS, we found that the Informix and Unix utilities that we use in our menus pretty much follow the $SHELL convention. However, there are some subtle differences in the way the various programs interpret the contents of $SHELL. The most straightforward solution we found was to set $SHELL equal to the pathname of a program that simply displays an error message and exits. We developed this approach basically by trial and error, so there's no guarantee that we haven't missed something. We are currently migrating to a scheme where each Informix user has a "normal" shell-level login-ID. All Informix applications will be run from the shell with a setuid start-up program. One of the motivations for doing this is to eliminate as many of the Unix utilities like e-mail as possible from the Informix app that are required for a locked-in login-ID. Walt. -- Walt Hultgren Internet: walt@rmy.emory.edu (IP 128.140.8.1) Emory University UUCP: {...,gatech,rutgers,uunet}!emory!rmy!walt 954 Gatewood Road, NE BITNET: walt@EMORY Atlanta, GA 30329 USA Voice: +1 404 727 0648