Re: tbmode -z KILL PROCESS
Posted in 1996
Malcolm Weallans wrote: > > Actually there is a way to run tbmode -z without being either root or > informix. Set up a proxy login with the same user id as informix but > with a restricted shell which only allows restricted commands. It > depends on the security of the UNIX system but I have done it before. > Yes, this way works, but I don't recommend it. If I remember correctly, some flavors of UNIX only allow you to create one restricted shell. Meaning that when you create a restricted shell, there is only one file which controls the commands that the restricted shell can run. Depending on the OS, there may also be some security risks. BTW, it is easy to confuse restricted shell rsh with remote shell. By writing a C program which does a setuid, you can do the following: 1) Audit and verify who ran it and from what account. 2) Place a secondary password within the program. 3) Create a timer to launch the command. 4) Wall a message to all the users that the engine is going down. 5) Run the command and exit without any security hassels. -Mikey BTW I'm not paranoid, its just my job to be paranoid. ;-)