This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
openbsd:shell [2019/12/05 04:17] jrmu |
openbsd:shell [2020/05/19 00:27] (current) jrmu |
||
---|---|---|---|
Line 17: | Line 17: | ||
} | } | ||
</code> | </code> | ||
+ | |||
+ | Update: hiding logs was causing problems | ||
We also hide logs in /var/logs and /var/www/logs | We also hide logs in /var/logs and /var/www/logs | ||
Line 154: | Line 156: | ||
<code> | <code> | ||
export PS1="`whoami`$ " | export PS1="`whoami`$ " | ||
+ | </code> | ||
+ | |||
+ | <code> | ||
+ | # chmod -R o-rx /var/log | ||
+ | # chmod o-rx /var/run/utmp | ||
+ | # chmod o-r /var/log/wtmp* | ||
</code> | </code> | ||
Line 165: | Line 173: | ||
# chmod 750 /var/log | # chmod 750 /var/log | ||
# chmod o-rx /var/log/* | # chmod o-rx /var/log/* | ||
+ | # chmod -R o-rx /etc/mail | ||
</code> | </code> | ||
Line 201: | Line 210: | ||
Check /etc/groups to make sure that no user is a member of wheel. This will prevent them from su to root even if they know the password. | Check /etc/groups to make sure that no user is a member of wheel. This will prevent them from su to root even if they know the password. | ||
+ | In /etc/ssh/sshd_config, turn off X11 forwarding | ||
+ | |||
+ | Create symlinks for users so they don't complain: | ||
+ | |||
+ | <code> | ||
+ | ln -s /usr/local/bin/tclsh8.6 /usr/local/bin/tclsh | ||
+ | ln -s /usr/local/bin/python3.7 /usr/local/bin/python | ||
+ | </code> | ||
+ | |||
+ | You will want to have /var/www/etc/resolv.conf to allow DNS lookup inside the chroot: | ||
+ | |||
+ | <code> | ||
+ | # mkdir /var/www/etc/ | ||
+ | # cp /etc/resolv.conf /var/www/etc/ | ||
+ | # chown -R www:daemon /var/www/etc | ||
+ | </code> |