Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

fellow employees

Thread Tools
 
Search this Thread
 
Old 01 August 2002, 01:45 PM
  #1  
krankyd
Scooby Regular
Thread Starter
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Angry

I just had someone from my department run the following command on one of *my* unix machines (as user root, of course, and the root home area is /)

eurcic1:/ cd /usr1/data/incoming
eurcic1:/ ls
~$myfile
~$myfile1
eurcic1:/ rm -rf ~$myfile
error - can't stat /
error - can't stat /
error - can't stat /
error - can't stat /
^C

It's dead jim!!!
Old 01 August 2002, 02:06 PM
  #2  
Andrewza
Scooby Regular
 
Andrewza's Avatar
 
Join Date: Jan 2002
Posts: 667
Likes: 0
Received 0 Likes on 0 Posts
Post

Safety net

apathy# whoami
root
apathy# cd ~
apathy# pwd
/root
apathy#
Old 01 August 2002, 02:07 PM
  #3  
David_Wallis
Scooby Regular
 
David_Wallis's Avatar
 
Join Date: Nov 2001
Location: Leeds - It was 562.4bhp@28psi on Optimax, How much closer to 600 with race fuel and a bigger turbo?
Posts: 15,239
Likes: 0
Received 1 Like on 1 Post
Post

its about time i learnt linux / unix

David
Old 01 August 2002, 02:20 PM
  #4  
krankyd
Scooby Regular
Thread Starter
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Post

>> safety net.

I know that now...
grrr..

but it's not me that issued the command!!!!!!!


*******s!!!


Old 01 August 2002, 02:50 PM
  #5  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

Why do they have root access then ?

S
Old 01 August 2002, 03:36 PM
  #6  
stevencotton
Scooby Regular
 
stevencotton's Avatar
 
Join Date: Jan 2001
Location: behind twin turbos
Posts: 2,710
Likes: 0
Received 1 Like on 1 Post
Post

He doesn't now
Old 01 August 2002, 05:52 PM
  #7  
krankyd
Scooby Regular
Thread Starter
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Post

you rekion?

Check out the following e-mail!!

As XXXX is in the Siebel team, I am told that they need root access for Siebel administration. Its not very logical to take root permissions away from him on infrastructure servers because the risk is too high, but then continue to allow root access on BCC production systems.

Please advise if we should limit his permissions or just tell him to use root only for Siebel tasks


SHOCKER!

And after I had a 10 minute argument with one of the management about restricting ALL root access to all servers. IMHO, no-one apart from the admins shoud have root access. if you want root access you should write to your manager requesting it with a business need outlined. Otherwise, no way!!

Trending Topics

Old 01 August 2002, 05:54 PM
  #8  
Andrewza
Scooby Regular
 
Andrewza's Avatar
 
Join Date: Jan 2002
Posts: 667
Likes: 0
Received 0 Likes on 0 Posts
Post

Why not use something like sudo? let's users access certain commands as root, not perfect, but you might be able to limit them to inflicting pain on their applications only
Old 01 August 2002, 06:06 PM
  #9  
krankyd
Scooby Regular
Thread Starter
 
krankyd's Avatar
 
Join Date: May 2001
Posts: 672
Likes: 0
Received 0 Likes on 0 Posts
Unhappy

mmmm. but the bank don't allow freeware....

bugger!
Old 01 August 2002, 07:48 PM
  #10  
stevem2k
Scooby Regular
 
stevem2k's Avatar
 
Join Date: Sep 2001
Location: Kingston ( Surrey, not Jamaica )
Posts: 4,670
Likes: 0
Received 0 Likes on 0 Posts
Post

Give them a shell front end to execute their 'admin' tasks. Menu driven with setuid to execute tasks *absolutely* requiring root, trap any attempts at ctrl-c or ctrl-z to stop them shelling out. I'm sure that most of their tasks don't really require root.

The other thing to do is to leave them as is - but insist the department head signs an agreement that next time they fcsk up any problems will be fixed on a 'best effort only, low priority' basis. Wait till they break it and go on holiday for a fortnight.

Steve "You'll never take my root password alive" M

Old 01 August 2002, 10:39 PM
  #11  
blp
Scooby Regular
 
blp's Avatar
 
Join Date: Mar 1999
Posts: 411
Likes: 0
Received 0 Likes on 0 Posts
Post

Interesting. No one accessing a Siebel Apps Server or File Server should need to do that stuff. Big Brother Siebel get most upset if you start playing around at DB level....
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
DJZsti
Subaru Parts
5
08 February 2019 07:41 PM
ru1nedwrx
Suspension
0
21 September 2015 01:59 PM
KOEScoob
ScoobyNet General
6
17 September 2015 03:51 PM
RESSE
ScoobyNet General
42
14 December 2000 07:46 PM
Scott J Davies
ScoobyNet General
6
12 September 2000 10:26 AM



Quick Reply: fellow employees



All times are GMT +1. The time now is 08:41 AM.