From owner-freebsd-security Thu Nov 16 1:58: 0 2000 Delivered-To: freebsd-security@freebsd.org Received: from blues.jpj.net (blues.jpj.net [204.97.17.146]) by hub.freebsd.org (Postfix) with ESMTP id 943A737B4CF for ; Thu, 16 Nov 2000 01:57:58 -0800 (PST) Received: from localhost (trevor@localhost) by blues.jpj.net (right/backatcha) with ESMTP id eAG9vbM15360; Thu, 16 Nov 2000 04:57:37 -0500 (EST) Date: Thu, 16 Nov 2000 04:57:37 -0500 (EST) From: Trevor Johnson To: Will Mitayai Keeso Rowe Cc: security@FreeBSD.ORG Subject: RE: Shell acces with not specified shell in /etc/shells (Re: problem using sysinstall) In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org > does ssh check /etc/shells ? Users can run arbitrary commands with ssh, without a shell ever being invoked or (at least on my 4.1.1-RELEASE system) anything being logged. Try this: ssh localhost ls last | head -- Trevor Johnson http://jpj.net/~trevor/gpgkey.txt To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message