Re: [SLUG] Todays puzzle

From: Eben King (eben1@tampabay.rr.com)
Date: Tue Mar 07 2006 - 13:02:47 EST


On Tue, 7 Mar 2006, Kwan Lowe wrote:

>> My problem is with the mepis system because someone will shut the system
>> down even though I have taken all the Icons off the desktop except
>> firefox so whoever does it has to make an effort and it isn't just a
>> mistake. What I would like is the system to boot up into firefox and if
>> they exit firefox it would start up again in 10 seconds. I don't even
>> know if this is doable. Any ideas? TIA Maury
>
> A couple possibilities:
>
> 0) Don't even load a window manager. There's a linux-kiosk project that
> has hacked twm to load instead of the wm.

twm _is_ a window manager -- Tabbed Window Manager. It's a minimal wm, to
be sure. It's not an environment like KDE or GNOME.

> Kill firefox and the X-server exits and respawns via inittab.

I think you'd have to have _no_ window manager for that to happen, or have
the wm tweaked so that it exits when FF does.

> 1) Remove execute permissions for /sbin/shutdown for group and other.

Read too, else Joe User can copy it, make the copy executable and run that,
or do "/lib/ld-linux.so<tab> /sbin/shutdown" no matter its execute permission.

Could the following text be the cause of the mysterious shutdowns?

from shutdown(8):
,--
| shutdown can be called from init(8) when the magic keys CTRL-ALT-DEL
| are pressed, by creating an appropriate entry in /etc/inittab. This
| means that everyone who has physical access to the console keyboard can
| shut the system down.
'--

Absent any obvious reason, I'd say you've been hacked. Check
/var/log/messages* for things like "foo 'su'd to root" or "root logged in
from bar", not long before messages like "system is shutting down". Do
"last | head" and look for odd logins. Take network interfaces down "for
testing" for a day or two one at a time and see if the shutdowns stop. Of
course, if you take down the outbound interface, people will stop using it,
so that's not a good test. But you can still check the wireless that way.

-- 
-eben    ebQenW1@EtaRmpTabYayU.rIr.OcoPm    home.tampabay.rr.com/hactar

Q: What kind of modem did Jimi Hendrix use? A: A purple Hayes. ----------------------------------------------------------------------- This list is provided as an unmoderated internet service by Networked Knowledge Systems (NKS). Views and opinions expressed in messages posted are those of the author and do not necessarily reflect the official policy or position of NKS or any of its employees.



This archive was generated by hypermail 2.1.3 : Fri Aug 01 2014 - 19:43:54 EDT