2005/03/14 pam_console.so

RedHat gives console users additional privileges through this PAM module. If an ordinary user logs in at one of the console screen, and no other user is already logged in at another console tty, all the files listed in /etc/security/console.perms have their permissions and ownership changed so that user owns them. It's quite a list of files, including the floppy drive, cd, keyboard and so on. You can, of course, edit this file to cut down on the list.

In addition to files, /etc/security/console.apps/ contains references to applications that this console user can run. The references are files, but the contents are interesting in that "man console.apps" says:


Hate these ads?

The /etc/security/console.apps/ directory should contain one file per application that wishes to allow access to console users. The filename should be the same as the servicename, and the contents are irrelevant; the file may be a zero-length file. The application that the file is used by is free to specify the contents in any way that is useful for it.

Indeed, while most of the files there have similar content, at least one (xserver) is empty on my machine. However, just because a file is there does NOT mean that the console user can have free rein: the program to be run must be PAM aware, and pam_console.so must be referenced in its /etc/pam.d setup. On my RedHat system, for example, /etc/security/console.apps/ contains quite a few files, but only a few of them have the required pam.d entries, so the console user would not be able to use them.

If you want to remove one or more of those that are left, I suggest removing the files from /etc/security/console.apps/ AND commenting out the pam_console.so entry in the /etc/pam.d file. That makes it definite that the user won't have the access if files get accidentally or maliciously restored to the console.apps directory.

Whether console users should have ANY extra privileges is another discussion. It's certainly convenient, but convenience is always a threat to security. Small privileges can be escalated to major security breaches. That's why I recommended doing both removals above: the more roadblocks in place, the less likely anything can slip by. It's the same reason that I shut off unneeded services even if those services are blocked at the firewall: if the firewall fails, at least the services aren't waiting with open arms. In this case, if the decision was made to not grant any extra privilege, you might consider removing or renaming the pam_console.so library also - just another security step, though perhaps more drastic than most as it would make the console pretty much unusable for ordinary users.




Enter your email address for automatic notification of new posts here
(be sure to whitelist 'feedburner.com' if you use spam filtering)

Or use any RSS reader

Delivered by FeedBurner

cartoon
Need eyes on the ground at your customer's site?
Installation and light training Boston and New England
Reliable and experienced, punctual and professional.


Views for this page
Today This Week This Month This Year  Overall
3356591 3,048

Have you tried Searching this site?

Unix/Linux/Mac OS X support by phone, email or on-site: Support Rates

This is a Unix/Linux resource website. It contains technical articles about Unix, Linux and general computing related subjects, opinion, news, help files, how-to's, tutorials and more. We appreciate comments and article submissions.

Publishing your articles here

pavatar.jpg
More:
       - Security
       - Linux
       - Unix




Unix/Linux Consultants


http://echo3.net/ Unix/Linux Custom Applications, Web Hosting, C/C++ Programming Courses


UBB Computer Services Support for Openserver, Unixware and Linux. Windows integration with Unix/Linux servers. Hardware, Backup and Networking issues. Located near Sacramento CA, we provide onsite support throughout Northern CA and Nationwide via remote access. We are a SCO Authorized Partner and a Microlite BackupEdge Certified Reseller.


http://www.m3ipinc.com Security, firewalls, ids, audits, vulnerability assesments, BS7799, HIPAA, GLB, incident handling



Twitter
  • Nov 23 08:34
    So many sites tell me what I MUST do: focus on a niche, have an elevator pitch, all that.. naaaw - I LIKE being scatter brained.
  • Nov 23 07:35
    Bailing out GM et al. is like bailing out SCO. It makes me angry that they even TALK about it.









Change Congress


Related Posts