- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- /sbin/shutdown and /sbin/init
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:18 AM
06-20-2002 05:18 AM
I just found that the permissions for the two files are -r-xr-xr-x.
Does it mean all people can shutdwon the system?
CRYSTAL
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:23 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:24 AM
06-20-2002 05:24 AM
Re: /sbin/shutdown and /sbin/init
shutdown is controlled by shutdown.allow
I'm fairly sure init makes kernel calls which the average user is not allowed to do.
Tim
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:24 AM
06-20-2002 05:24 AM
Re: /sbin/shutdown and /sbin/init
Pete
Pete
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:25 AM
06-20-2002 05:25 AM
Re: /sbin/shutdown and /sbin/init
No. Shutdown does extra checking to ensure only a superuser can run it. Try it as a non root user and you will see.
The permissions on /sbin/shutdown should actually be 04555. You can verify this by doing;
swlist -a mode -l file|grep "/sbin/shutdown"
And it returns 04555 (at least on my 11.0 box it does).
/sbin/init should indeed be permission 0555.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:27 AM
06-20-2002 05:27 AM
Re: /sbin/shutdown and /sbin/init
See the owner and group of these files. Owner will be root and group will be sys. Hence all the users cannot execute.
If you make an entry in /etc/shutdown.allow then the users can shutdown the machine.
Piyush
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:28 AM
06-20-2002 05:28 AM
Re: /sbin/shutdown and /sbin/init
This setting is by default. I have checked several boxes, they are the same settings.
CRYSTAL
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:35 AM
06-20-2002 05:35 AM
Re: /sbin/shutdown and /sbin/init
I did check /usr/sbin/swlist -a mode -l file | grep "/sbin/shutdown" and it is 04555.
Does a regular user can run reboot or init?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 05:52 AM
06-20-2002 05:52 AM
Re: /sbin/shutdown and /sbin/init
A regular user cannot execute init or reboot.
It will give an error - "Must be a Super-User"
Give an ls -al /sbin/init and see the owner and group for this file.
The owner of these files is root and the group is sys. So only the user root or any other users in the group sys can execute these commands.
Piyush
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-20-2002 06:00 AM
06-20-2002 06:00 AM
Re: /sbin/shutdown and /sbin/init
Even reboot will tell you " Permission denied" when executed by any other user except root.
If all the users will have the previledge to use the shutdown/init/reboot commands then we system admins may have a "TOUGH TIME" !!!
Piyush
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
08-07-2002 02:30 AM
08-07-2002 02:30 AM
Re: /sbin/shutdown and /sbin/init
If an abnormal channel of access to /sbin/shutdown is exploited, with the setuid bit set, the shutdown binary is exposed to potential buffer overflows even though none has been discovered yet (as far as I can recall i.e. I have not done a thorough search for buffer overflow vulnerabilities on the shutdown binary). Thus, the security principle of least privileges tells us that such risks should be mitigated where possible, which is dependent on whether the configuration without setuid bits set is supported by HP.
Hope this helps. Regards.
Steven Sim Kok Leong