Solved: no !, yet menus work
Posted in 1994
My original question: ---------------------------------------------------------------------- > > Is there a way to keep users from being able to access the shell from > either the user menus, or a sformbld form (no 4gl available). > > This is Unix, running SQL 2.10.03G (pre-engine revision level). > > I guess what I am looking for is a way to use rsh, or the last field in the > password file to keep this from happening. Thanks for tips... > > Ann ------------------------------------------------------------ Bobs answer: ------------------------------------------------------------- Ann, In the user's .profile you can set a variable SHELL to /dev/null: SHELL=/dev/null export SHELL or SHELL="" export SHELL By changing the permissions/ownership of the .profile, the user won't be able to change it either. chown .profile root chmod 755 .profile ------------------------------------------------------------------- * Bob Beaulieu (bobb@netcom.com) eztravel@netcom.com * * Tel: 408-978-0808 Fax: 408-978-7024 * * Corporate Travel Services * ------------------------------------------------------------------- --------------------------------------------------------------------------- My final solution: --------------------------------------------------------------------------- Problem with Bob's solution was it also negated the use of [P]rograms that were shell scripts from inside the user menus. The Informix Tech Help Line (TIM did immediately fax me an answer!) sent the following script from Tech Notes Spr 90 I believe: We modified as noted below; we call it /bin/shell. #include <stdio.h> int main(argc, argv) int argc; char *argv[]; { char *ptr; char *strrchr(); if (argc >=3) { ptr=strrchr(argv[2], '/'); ++ptr; if (*ptr != '_') printf("Sorry, No shell commands allowed!\\n"); else (void) system(argv[2]); } exit(0); } ...as we modified it. We did change the code to allow for shell commands in our user menus that had /f_u_l_l paths. The original code only allowed shell scripts which BEGAN with an "_" to run; but did NOT allow for /filesys/_prog to run (just _prog). Since our users all stay at HOME and run user menus from their DBPATH and shell scripts which also live only in DBPATH (not their PATH), they must be run with full pathnames. So...we modified this code. It will run any shell command whether or not it begins with a /, which has /_ as the beginning of the last entry(basename) in the path. If the command does not meet these specifications, it returns the Sorry...message. I linked all my .sh files to _xxxx.sh. I modified the user menus to call the files by /filesys/_xxxx.sh names. SOME of our users are allowed shell access, and need to use the ! escape. SOME do not. For those users not allowed shell, we inserted the SHELL=/bin/shell; export SHELL into their .profiles, and exec isql dbname -u main at the end of the profile. (I suppose I could also have made /bin/shell the last entry in the password file). Perms on their .profile are root and 711. Thus they are locked into informix menus and will leave the system when they <e>xit the menus. They cannot !bang out. Yet they can run all the [P] shellscripts. They cannot modify their .profile as they cannot reach it. The other users can !bang out, and run the shellscripts because they actually exist in Unix with the _xxx.sh name called by the menus, thanks to the link. Hope this helps someone else w/the same problem! Ann