[X2Go-Commits] page changed: wiki:security:rbash

wiki-admin at x2go.org wiki-admin at x2go.org
Mon Nov 3 14:07:18 CET 2014


A page in your DokuWiki was added or changed. Here are the details:

Date        : 2014/11/03 13:07
Browser     : Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/37.0.2062.120 Chrome/37.0.2062.120 Safari/537.36
IP-Address  : 94.198.62.204
Hostname    : fb-n15-11.unbelievable-machine.net
Old Revision: http://wiki.x2go.org/doku.php/wiki:security:rbash?rev=1414843334
New Revision: http://wiki.x2go.org/doku.php/wiki:security:rbash
Edit Summary: [rbash as default shell (optional)] 
User        : woglinde

@@ -96,25 +96,5 @@
  
  ===== Security concerns =====
  There could be still problems to brake out of rbash, no one yet made a security audit of the linked x2go scripts, if they allow the execution of a real shell
  via options.
- ====== rbash as default shell (optional)======
  
- If rbash is also set as the default shell via /etc/passwd or some other mechanism, the sessioncleanup skripts needs
- to be fixed too.
- 
- In
- <code bash>
-
/usr/sbin/x2gocleansessions 
- </code>
- 
- the lines with
- 
- <code bash>
- system("su", "@sinfo[11]", "-c"
- </code>
- 
- needs to be changed to
- 
- <code bash>
- system("su", "@sinfo[11]", "-s", "/bin/bash", "-c",
- </code>



-- 
This mail was generated by DokuWiki at
http://wiki.x2go.org/



More information about the x2go-commits mailing list