<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems using /bin/false as a shell user in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027538#M131880</link>
    <description>This may help....&lt;BR /&gt;&lt;BR /&gt;Problem Description&lt;BR /&gt;&lt;BR /&gt;When doing a su within the NIS environment, I get a memory&lt;BR /&gt;fault core dump on HP-UX 11.0. I have the latest NIS patch.&lt;BR /&gt;What is causing this problem?&lt;BR /&gt;&lt;BR /&gt;Configuration Info&lt;BR /&gt;&lt;BR /&gt;Operating System - HPUX&lt;BR /&gt;Version - 11.0&lt;BR /&gt;Hardware System - HP 9000&lt;BR /&gt;Series - T500&lt;BR /&gt;&lt;BR /&gt;Solution&lt;BR /&gt;&lt;BR /&gt;su(1) can dump core when used on a system with NIS, because NIS uses&lt;BR /&gt;heap memory that su(1) expects to be initialized to all "\0".&lt;BR /&gt;Apply the new su patch PHCO_15232 in order to solve this problem.&lt;BR /&gt;&lt;BR /&gt;Patches can be superseded by subsequent versions; be sure to load&lt;BR /&gt;the current version.&lt;BR /&gt;</description>
    <pubDate>Fri, 18 Jul 2003 14:09:21 GMT</pubDate>
    <dc:creator>Anthony deRito</dc:creator>
    <dc:date>2003-07-18T14:09:21Z</dc:date>
    <item>
      <title>Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027536#M131878</link>
      <description>Dear friends, &lt;BR /&gt;&lt;BR /&gt;I'm having problems when I use /bin/false as a shell user in /etc/passwd. When I run "su - user" the comand shows a coredump:&lt;BR /&gt;&lt;BR /&gt;# su - user&lt;BR /&gt;su: No shell&lt;BR /&gt;Memory fault(coredump)&lt;BR /&gt;&lt;BR /&gt;I think this is a security problem. Is this correct? Can anyone help me? Is there any patch   for this problem?&lt;BR /&gt;&lt;BR /&gt;I am using HP-UX 11.00.&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;&lt;BR /&gt;Jansen.</description>
      <pubDate>Fri, 18 Jul 2003 14:00:32 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027536#M131878</guid>
      <dc:creator>Jansen Sena_1</dc:creator>
      <dc:date>2003-07-18T14:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027537#M131879</link>
      <description>Hi,&lt;BR /&gt;check this:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x92f1e822e739d711abdc0090277a778c,00.html" target="_blank"&gt;http://forums.itrc.hp.com/cm/QuestionAnswer/1,,0x92f1e822e739d711abdc0090277a778c,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Enrico.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 18 Jul 2003 14:09:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027537#M131879</guid>
      <dc:creator>Enrico P.</dc:creator>
      <dc:date>2003-07-18T14:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027538#M131880</link>
      <description>This may help....&lt;BR /&gt;&lt;BR /&gt;Problem Description&lt;BR /&gt;&lt;BR /&gt;When doing a su within the NIS environment, I get a memory&lt;BR /&gt;fault core dump on HP-UX 11.0. I have the latest NIS patch.&lt;BR /&gt;What is causing this problem?&lt;BR /&gt;&lt;BR /&gt;Configuration Info&lt;BR /&gt;&lt;BR /&gt;Operating System - HPUX&lt;BR /&gt;Version - 11.0&lt;BR /&gt;Hardware System - HP 9000&lt;BR /&gt;Series - T500&lt;BR /&gt;&lt;BR /&gt;Solution&lt;BR /&gt;&lt;BR /&gt;su(1) can dump core when used on a system with NIS, because NIS uses&lt;BR /&gt;heap memory that su(1) expects to be initialized to all "\0".&lt;BR /&gt;Apply the new su patch PHCO_15232 in order to solve this problem.&lt;BR /&gt;&lt;BR /&gt;Patches can be superseded by subsequent versions; be sure to load&lt;BR /&gt;the current version.&lt;BR /&gt;</description>
      <pubDate>Fri, 18 Jul 2003 14:09:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027538#M131880</guid>
      <dc:creator>Anthony deRito</dc:creator>
      <dc:date>2003-07-18T14:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027539#M131881</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;The /bin/false is not a shell but just a script for auto exit. It is given to ftp users to fix a possible security problem.&lt;BR /&gt;&lt;BR /&gt;You cannot use it for a normal user.&lt;BR /&gt;su needs a realshell or it aborts.&lt;BR /&gt;&lt;BR /&gt; cat /bin/false&lt;BR /&gt;&lt;BR /&gt;# @(#) $Revision: 64.1 $&lt;BR /&gt;exit 1&lt;BR /&gt;&lt;BR /&gt;# what /bin/false&lt;BR /&gt;/bin/false:&lt;BR /&gt;         $Revision: 64.1 $&lt;BR /&gt;&lt;BR /&gt;file /bin/false&lt;BR /&gt;/bin/false:     commands text&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;                 Steve Steel&lt;BR /&gt;</description>
      <pubDate>Fri, 18 Jul 2003 14:14:19 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027539#M131881</guid>
      <dc:creator>Steve Steel</dc:creator>
      <dc:date>2003-07-18T14:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027540#M131882</link>
      <description>This is a rather useless exercise. Even if you include /bin/false in /etc/shells, the su command is going to then spawn /bin/false after setting the user id and group id to the new user. Of course, /bin/false will immediately exit and you are back in the parent shell as the original user.&lt;BR /&gt;&lt;BR /&gt;User's with /bin/false or similar shells can really only change the UID with the setuid() system call with C. If you want to do this in a scripting language,use Perl. You can use the POSIX::setuid Perl function or simply reassign $&amp;lt;.&lt;BR /&gt;</description>
      <pubDate>Fri, 18 Jul 2003 14:23:01 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027540#M131882</guid>
      <dc:creator>A. Clay Stephenson</dc:creator>
      <dc:date>2003-07-18T14:23:01Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027541#M131883</link>
      <description>Guys, &lt;BR /&gt;&lt;BR /&gt;I'm using /bin/false as a user shell because I need configure ftp only users. But, I think that coredump is a local security problem. On Linux, for example, when I configure a user's shell to /bin/false and I run su, the user logon process fail but I don't have coredump.</description>
      <pubDate>Fri, 18 Jul 2003 15:07:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027541#M131883</guid>
      <dc:creator>Jansen Sena_1</dc:creator>
      <dc:date>2003-07-18T15:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problems using /bin/false as a shell user</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027542#M131884</link>
      <description>Well, you are expected to use /bin/false as a shell for FTP only ID's.&lt;BR /&gt;&lt;BR /&gt;Because you get a core dump with su - ID and they have no shell is not a security issue, it's a login/pam patch issue where login is not aborting correctly when you have no valid shell and force login.&lt;BR /&gt;&lt;BR /&gt;Make sure your patched correctly, but more importantly... Dont test your ID's with su!  The only way to test the ID is to attemp different login in methods (telnet, rsh, ftp).  Using su ftponlyid will not show you anything about the ID.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Shannon</description>
      <pubDate>Fri, 18 Jul 2003 15:58:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/problems-using-bin-false-as-a-shell-user/m-p/3027542#M131884</guid>
      <dc:creator>Shannon Petry</dc:creator>
      <dc:date>2003-07-18T15:58:54Z</dc:date>
    </item>
  </channel>
</rss>

