Re: Death to toor

From: John Baldwin (jhb_at_FreeBSD.org)
Date: 06/15/05

  • Next message: David O'Brien: "Re: Death to toor"
    To: freebsd-arch@freebsd.org
    Date: Wed, 15 Jun 2005 16:55:52 -0400
    
    

    On Saturday 11 June 2005 10:54 pm, David O'Brien wrote:
    > On Thu, Jun 09, 2005 at 04:40:19PM -0700, John Baldwin wrote:
    > > Is there any good reason to keep the toor account around nowadays?
    >
    > Yes. Some of us use it.

    Well, that's why I asked.

    > > vipw has existed since 4.0BSD and chsh and friends have existed since
    > > 4.3BSD-Reno so I think that it's safe to say that folks are more than
    > > capable nowadays of changing root's default shell if desired.
    >
    > I wouldn't say we are totally safe changing root's default shell away
    > from /bin/csh. We still see people give the advice that one should not
    > change root's default shell.

    I never mentioned that FreeBSD would change root's default shell. All I said
    is that people have had tools available to them to easily change root's shell
    on their boxes since at least the early 1990s if they don't want to
    use /bin/csh on a particular box. Stop putting words in my mouth please.

    > > Also,
    > > '/bin/csh' and '/bin/sh' aren't very hard to type once you are logged
    > > in as root whatever the default shell may be.
    >
    > We could default to only /bin/sh as the login shell globally.
    > 'csh', 'zsh', 'bash' aren't very hard to type once you are logged in.

    *sigh* EOFFINWEEDS. To twist this another way, when we create user accounts
    with adduser, we don't add 4 different variations of every user account so
    that everyone can pick a different user name to get sh, csh, zsh, or bash for
    their shell. The fact that we do this for root and no one else is
    inconsistent. The fact that it uses UID 0 also means that it's always
    showing up in people's security run checks as a non-root user with a UID of
    0. Maybe that security check should be dumped instead.

    Also, note that according to the FAQ, toor exists for bash support,
    not /bin/sh and apparently used to be installed by the bash port as part of
    its install. CVS says it has been around since 386BSD though, so I'm
    guessing that it wasn't ever a feature of the bash port per se, but maybe
    bash's own install scripts.

    -- 
    John Baldwin <jhb@FreeBSD.org>  <><  http://www.FreeBSD.org/~jhb/
    "Power Users Use the Power to Serve"  =  http://www.FreeBSD.org
    _______________________________________________
    freebsd-arch@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-arch
    To unsubscribe, send any mail to "freebsd-arch-unsubscribe@freebsd.org"
    

  • Next message: David O'Brien: "Re: Death to toor"

    Relevant Pages

    • Re: Crash upon accessing View menu in Windows Explorer
      ... if the same thing happens with another admin account it may ... > 1) The problem occurs not just in Windows Explorer and My Computer, etc., ... > 4) I checked which Shell Extensions (using the Shell Viewer program you ... > similar Shell Extension called $Address, ...
      (microsoft.public.windowsxp.general)
    • Re: Crash upon accessing View menu in Windows Explorer
      ... own account. ... I checked which Shell Extensions (using the Shell Viewer program you ... similar Shell Extension called $Address, also a Shell Browser UI ...
      (microsoft.public.windowsxp.general)
    • RE: User?s and Shells
      ... the shell as well the password for an account. ... Disabling the password makes ... The ideal solution is to have a binary program for the account shell ... defense in depth/layers is the key to security. ...
      (Focus-Linux)
    • Re: Only an ftp account
      ... > You may also want to add that user to /etc/ftpchroot which will chroot ... >> How would I be able to give an account to someone where they can only ... >> login and use FTP? ... Let me just point out that just changing the shell to /sbin/nologin ...
      (FreeBSD-Security)
    • Re: Remove Taskbar from the Desktop
      ... If you make the change while logged on to the account you want restricted, you'll have to log off/log on to see the change. ... Doug Knox, MS-MVP Windows Media Center\Windows Powered Smart Display\Security ... >> You may want to look at replacing the Shell statement in the Registry. ... >>> Johnny ...
      (microsoft.public.windowsxp.security_admin)