Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

fellow employees

Thread Tools
 
Search this Thread
 
Old Aug 1, 2002 | 01:45 PM
  #1  
krankyd's Avatar
krankyd
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 672
Likes: 0
Angry

I just had someone from my department run the following command on one of *my* unix machines (as user root, of course, and the root home area is /)

eurcic1:/ cd /usr1/data/incoming
eurcic1:/ ls
~$myfile
~$myfile1
eurcic1:/ rm -rf ~$myfile
error - can't stat /
error - can't stat /
error - can't stat /
error - can't stat /
^C

It's dead jim!!!
Reply
Old Aug 1, 2002 | 02:06 PM
  #2  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Post

Safety net

apathy# whoami
root
apathy# cd ~
apathy# pwd
/root
apathy#
Reply
Old Aug 1, 2002 | 02:07 PM
  #3  
David_Wallis's Avatar
David_Wallis
Scooby Regular
 
Joined: Nov 2001
Posts: 15,239
Likes: 1
From: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Post

its about time i learnt linux / unix

David
Reply
Old Aug 1, 2002 | 02:20 PM
  #4  
krankyd's Avatar
krankyd
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 672
Likes: 0
Post

>> safety net.

I know that now...
grrr..

but it's not me that issued the command!!!!!!!


*******s!!!


Reply
Old Aug 1, 2002 | 02:50 PM
  #5  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Post

Why do they have root access then ?

S
Reply
Old Aug 1, 2002 | 03:36 PM
  #6  
stevencotton's Avatar
stevencotton
Scooby Regular
 
Joined: Jan 2001
Posts: 2,710
Likes: 1
From: behind twin turbos
Post

He doesn't now
Reply
Old Aug 1, 2002 | 05:52 PM
  #7  
krankyd's Avatar
krankyd
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 672
Likes: 0
Post

you rekion?

Check out the following e-mail!!

As XXXX is in the Siebel team, I am told that they need root access for Siebel administration. Its not very logical to take root permissions away from him on infrastructure servers because the risk is too high, but then continue to allow root access on BCC production systems.

Please advise if we should limit his permissions or just tell him to use root only for Siebel tasks


SHOCKER!

And after I had a 10 minute argument with one of the management about restricting ALL root access to all servers. IMHO, no-one apart from the admins shoud have root access. if you want root access you should write to your manager requesting it with a business need outlined. Otherwise, no way!!
Reply

Trending Topics

Old Aug 1, 2002 | 05:54 PM
  #8  
Andrewza's Avatar
Andrewza
Scooby Regular
 
Joined: Jan 2002
Posts: 667
Likes: 0
Post

Why not use something like sudo? let's users access certain commands as root, not perfect, but you might be able to limit them to inflicting pain on their applications only
Reply
Old Aug 1, 2002 | 06:06 PM
  #9  
krankyd's Avatar
krankyd
Thread Starter
Scooby Regular
 
Joined: May 2001
Posts: 672
Likes: 0
Unhappy

mmmm. but the bank don't allow freeware....

bugger!
Reply
Old Aug 1, 2002 | 07:48 PM
  #10  
stevem2k's Avatar
stevem2k
Scooby Regular
 
Joined: Sep 2001
Posts: 4,670
Likes: 0
From: Kingston ( Surrey, not Jamaica )
Post

Give them a shell front end to execute their 'admin' tasks. Menu driven with setuid to execute tasks *absolutely* requiring root, trap any attempts at ctrl-c or ctrl-z to stop them shelling out. I'm sure that most of their tasks don't really require root.

The other thing to do is to leave them as is - but insist the department head signs an agreement that next time they fcsk up any problems will be fixed on a 'best effort only, low priority' basis. Wait till they break it and go on holiday for a fortnight.

Steve "You'll never take my root password alive" M

Reply
Old Aug 1, 2002 | 10:39 PM
  #11  
blp's Avatar
blp
Scooby Regular
 
Joined: Mar 1999
Posts: 411
Likes: 0
Post

Interesting. No one accessing a Siebel Apps Server or File Server should need to do that stuff. Big Brother Siebel get most upset if you start playing around at DB level....
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
DJZsti
Subaru Parts
5
Feb 8, 2019 07:41 PM
ru1nedwrx
Suspension
0
Sep 21, 2015 01:59 PM
user 46373939
ScoobyNet General
6
Sep 17, 2015 03:51 PM
RESSE
ScoobyNet General
42
Dec 14, 2000 07:46 PM
Scott J Davies
ScoobyNet General
6
Sep 12, 2000 10:26 AM




All times are GMT +1. The time now is 10:26 AM.