[X2Go-Commits] page changed: wiki:security:rbash

wiki-admin at x2go.org wiki-admin at x2go.org
Sat Nov 1 10:57:23 CET 2014


A page in your DokuWiki was added or changed. Here are the details:

Date        : 2014/11/01 09:57
Browser     : Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/37.0.2062.120 Chrome/37.0.2062.120 Safari/537.36
IP-Address  : 79.228.221.115
Hostname    : p4FE4DD73.dip0.t-ipconnect.de
Old Revision: http://wiki.x2go.org/doku.php/wiki:security:rbash?rev=1414834038
New Revision: http://wiki.x2go.org/doku.php/wiki:security:rbash
Edit Summary: [Bring the path back to some scripts] 
User        : woglinde

@@ -91,8 +91,11 @@
  <code bash>
  export PATH=/bin:/usr/bin:/sbin:/usr/sbin
  </code>
  
+ ====== Security concerns ======
+ There could be still problems to brake out of rbash, no one yet made a security audit of the linked x2go scripts, if they allow the execution of a real shell
+ via options.
  ====== rbash as default shell (optional)======
  
  If rbash is also set as the default shell via /etc/passwd or some other mechanism, the sessioncleanup
skripts needs
  to be fixed too.



-- 
This mail was generated by DokuWiki at
http://wiki.x2go.org/



More information about the x2go-commits mailing list