{"id":11571,"date":"2018-02-23T04:30:08","date_gmt":"2018-02-23T12:30:08","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/02\/23\/news-5342\/"},"modified":"2018-02-23T04:30:08","modified_gmt":"2018-02-23T12:30:08","slug":"news-5342","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2018\/02\/23\/news-5342\/","title":{"rendered":"Clever, redefined"},"content":{"rendered":"<p><strong>Credit to Author: Sharky| Date: Fri, 23 Feb 2018 03:00:00 -0800<\/strong><\/p>\n<p>It&#8217;s the 1990s, and this pilot fish is hired at a big international company to maintain a group of Linux servers &#8212; and they definitely need help.<\/p>\n<p>&#8220;My initial survey of the systems uncovered some serious security problems,&#8221; says fish. &#8220;Everything had been set up and users added with no regard to security.<\/p>\n<p>&#8220;As a temporary holding action, I set all the users&#8217; login shells to a custom restricted shell that allowed each user access to only the directories and commands necessary for their work while I analyzed all the systems, planned a decent security configuration for each, got approvals, did testing and, finally, implemented the new security.&#8221;<\/p>\n<p>The users hate the restricted shell almost as much as fish hates handling all the problems the users are having &#8212; and some users complain on a daily basis.<\/p>\n<p>But some do more than that. Fish discovers one clever user has come up with what he thinks is a cool hack to bypass the restricted shell. The hack: From inside the restricted command-line shell, the user runs the command to launch the standard command-line shell.<\/p>\n<p>And he thinks it works &#8212; though actually the command is automatically redirected and all the user gets is the restricted shell again.<\/p>\n<p>Meanwhile, fish works furiously to get the new security in place. And as soon as every Linux system is properly secured, he resets all the users&#8217; configurations back to a normal command shell.<\/p>\n<p>&#8220;A little while later, in checking how the users were doing, I discovered that the clever user was still running a command to escape from what he thought was still a restricted shell,&#8221; fish says. &#8220;He was issuing the specific command that invoked the restricted shell. So while everyone else was running a normal shell, this clever user was still restricted.<\/p>\n<p>&#8220;I didn&#8217;t tell him.&#8221;<\/p>\n<p style=\"font-size: 0.875em;\"><strong>Tell Sharky<\/strong> <i>your true tale of IT life at <a href=\"mailto:sharky@computerworld.com\" rel=\"nofollow\">sharky@computerworld.com<\/a>. You&#8217;ll score a sharp Shark shirt if I use it. Comment on today&#8217;s tale at <a href=\"https:\/\/plus.google.com\/u\/0\/communities\/113252326043973101081\" rel=\"nofollow\"><strong>Sharky&#8217;s Google+ community<\/strong><\/a>, and read thousands of great old tales in the <a href=\"http:\/\/www.computerworld.com\/search?query=+sharky&amp;s=d&amp;start=0\" title=\"Sharky's archives on easier-to-navigate pages\"><strong>Sharkives<\/strong><\/a>.<\/i><\/p>\n<p><em>Get Sharky&#8217;s outtakes from the IT Theater of the Absurd delivered directly to your Inbox. Subscribe now to the <a href=\"http:\/\/www.computerworld.com\/newsletters\/signup.html\" title=\"Daily Shark Newsletter subscription page\">Daily Shark Newsletter<\/a>.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3257613\/security\/clever-redefined.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Sharky| Date: Fri, 23 Feb 2018 03:00:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>It&#8217;s the 1990s, and this pilot fish is hired at a big international company to maintain a group of Linux servers &#8212; and they definitely need help.<\/p>\n<p>&#8220;My initial survey of the systems uncovered some serious security problems,&#8221; says fish. &#8220;Everything had been set up and users added with no regard to security.<\/p>\n<p>&#8220;As a temporary holding action, I set all the users&#8217; login shells to a custom restricted shell that allowed each user access to only the directories and commands necessary for their work while I analyzed all the systems, planned a decent security configuration for each, got approvals, did testing and, finally, implemented the new security.&#8221;<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3257613\/security\/clever-redefined.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714],"class_list":["post-11571","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11571","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=11571"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/11571\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=11571"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=11571"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=11571"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}