Hi there, It seems there's a bash privileged mode. Can anyone tell me what exactly that is and when/why one shoudl use it? Thanks, Sander ********************************************************************** Disclaimer This email is confidential and intended solely for the use of the individual to whom it is addressed. Any views or opinions presented are solely those of the author and do not necessarily represent those of the Azlan Holdings bv and/or subsidiary. If you are not the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing, or copying of this email is strictly prohibited. If you have received this email in error please notify Azlan Holdings MIS Helpdesk by telephone on +31 (0) 79 3443200. ********************************************************************** -- To unsubscribe send e-mail to suse-linux-e-unsubscribe@suse.com For additional commands send e-mail to suse-linux-e-help@suse.com Also check the FAQ at http://www.suse.com/Support/Doku/FAQ/
Hi, On Tue, 22 Feb 2000, Sander van Vugt wrote:
It seems there's a bash privileged mode. Can anyone tell me what exactly that is and when/why one shoudl use it?
Did you look into the bash man page? <SNIP> -p Turn on privileged mode. In this mode, the $ENV and $BASH_ENV files are not processed, shell functions are not inherited from the environment, and the SHELLOPTS variable, if it appears in the environment, is ignored. If the shell is started with the effective user (group) id not equal to the real user (group) id, and the -p option is not sup plied, these actions are taken and the effective user id is set to the real user id. If the -p option is supplied at startup, the effective user id is not reset. Turning this option off causes the effective user and group ids to be set to the real user and group ids. </SNIP> Looks like a way to restrict the shell in a certain way. But I am not real sure about the benefit of that... Bye, LenZ -- ------------------------------------------------------------------ Lenz Grimmer SuSE GmbH mailto:grimmer@suse.de Schanzaeckerstr. 10 http://www.suse.de/~grimmer 90443 Nuernberg, Germany -- To unsubscribe send e-mail to suse-linux-e-unsubscribe@suse.com For additional commands send e-mail to suse-linux-e-help@suse.com Also check the FAQ at http://www.suse.com/Support/Doku/FAQ/
Hi, I did find this information, but I also am not sure about the benefits. I'm not even sure I understand the man-information; it seems to claim that the default is a not-restricted shell, which means that on starting a subshell the effective UID is set to the real UID, which means some kind of restriction against abuse of SUID en SU, but i'm not sure about it. If it is, it seems like a nice feature. Bye, Sander Lenz Grimmer wrote:
Hi,
On Tue, 22 Feb 2000, Sander van Vugt wrote:
It seems there's a bash privileged mode. Can anyone tell me what exactly that is and when/why one shoudl use it?
Did you look into the bash man page?
<SNIP> -p Turn on privileged mode. In this mode, the $ENV and $BASH_ENV files are not processed, shell functions are not inherited from the environment, and the SHELLOPTS variable, if it appears in the environment, is ignored. If the shell is started with the effective user (group) id not equal to the real user (group) id, and the -p option is not sup plied, these actions are taken and the effective user id is set to the real user id. If the -p option is supplied at startup, the effective user id is not reset. Turning this option off causes the effective user and group ids to be set to the real user and group ids. </SNIP>
Looks like a way to restrict the shell in a certain way. But I am not real sure about the benefit of that...
Bye, LenZ
-- ------------------------------------------------------------------ Lenz Grimmer SuSE GmbH mailto:grimmer@suse.de Schanzaeckerstr. 10 http://www.suse.de/~grimmer 90443 Nuernberg, Germany
-- To unsubscribe send e-mail to suse-linux-e-unsubscribe@suse.com For additional commands send e-mail to suse-linux-e-help@suse.com Also check the FAQ at http://www.suse.com/Support/Doku/FAQ/
********************************************************************** Disclaimer This email is confidential and intended solely for the use of the individual to whom it is addressed. Any views or opinions presented are solely those of the author and do not necessarily represent those of the Azlan Holdings bv and/or subsidiary. If you are not the intended recipient, be advised that you have received this email in error and that any use, dissemination, forwarding, printing, or copying of this email is strictly prohibited. If you have received this email in error please notify Azlan Holdings MIS Helpdesk by telephone on +31 (0) 79 3443200. ********************************************************************** -- To unsubscribe send e-mail to suse-linux-e-unsubscribe@suse.com For additional commands send e-mail to suse-linux-e-help@suse.com Also check the FAQ at http://www.suse.com/Support/Doku/FAQ/
participants (2)
-
grimmer@suse.de
-
sander.van.vugt@azlan.nl