Restrict user account, prevent intruder from doing bad things

Hello,
I am currently planning and setting up a backup-server with ZFS. There will be daily snapshots of the filesystem (cron job).
Different machines connect automatically without a password via ssh (public/private key) and rsync their stuff to the backup server.
Each machine will connect to it's specific user (and therefore to it's own home directory) on the backup server. I thought that if one of the machines gets compromised (e.g. someone gets access to the private key) he only could access one home folder, nothing more. As there are daily snapshots, even it he deletes all files, they will still be there.
Is just adding a normal user per machine enough or should / can be done more to enhance security? As I said the user account is only for logging in and rsyncing stuff to the home directory.
E.g. disabling executing of applications except of rsync? Preventing fork bombs? Making it harder to run exploits? Other stuff I didn't think about?
Thanks
Last edited by cyberius (2013-02-17 08:23:39)

-Syu wrote:
You might also want to limit those user accounts themselves. If you only use them vor rsyncing, remove them from all unnecessary user groups (the "users" group in particular) and take away their shells.
On top of that, you may want to give each user a chroot jail, so they can't even write to /tmp for example.
I'm not too familliar with rsync yet. If you really need to make your other machines log in and execute rsync themselves over SSH, you might want to take a look at limited shells like lshell to only allow execution of that program.
Great, thank you! This was something I was looking for!
But if I take away the shell completely (e.g. chsh -s /sbin/nologin username), I think I won't be able to rsync via ssh right?
lshell sounds very promissing for my case, I will have a look at it!
edit: I found out that there is also a "--restricted" option for "bash", where one can disable PATH variables, changing directories. I will have a look.
Last edited by cyberius (2013-02-18 10:14:36)

Similar Messages

  • I'm an American living on a timed (though long-term) assignment in Ireland. I have both American and Irish bank accounts and addresses. I have two Qs. 1. Can I use the US Adobe site when in Ireland? Or will my physical location prevent me from doing so? 2

    I'm an American living on a timed (though long-term) assignment in Ireland. I have both American and Irish bank accounts and addresses. I have two Qs. 1. Can I use the US Adobe site when in Ireland? Or will my physical location prevent me from doing so? 2. I am working for a not-for-profit organization. Is there a special pricing plan for non-profits, similar to the plans for students, small business, etc? Thanks for whatever help you can give me. (P.S. As a potential customer and past user of Adobe products for 15  years, I find it INCREDIBLY FRUSTRATING that I cannot speak with any Adobe representative, but am continually re-routed instead to a public forum to get what I hope will be accurate information. Not good, Adobe. Your products are amazing. Your customer service leaves a lot to be desired. I don't mean that with disrespect, but as honest feedback.)

    Hi bookchic
    Thanks for your feedback.
    Non-profit pricing is available to eligible institutions via the VIP program which is sold by resellers - see Eligibility guide
    For details of resellers please check here: Adobe Platinum Partners – Value Incentive Plan
    If you wish to purchase an individual plan via Adobe.com the country of your Adobe ID will determine which site you order from.
    Kind regards
    Bev

  • When I disconnect my iphone 3gs(iOS) from computer, the device disappears from my itunes. This prevents me from doing a wireless sync. how do i fix it so that my device stays on itunes without having to plug it in all the time?

    When I disconnect my iphone 3gs(iOS) from computer, the device disappears from my itunes. This prevents me from doing a wireless sync. how do i fix it so that my device stays on itunes without having to plug it in all the time?
    it worked the first few times i did it but the next day after i closed out of itunes once, the device only appears when i plug in my phone.

    Whenever a menu choice is grayed out, that is because you have Restrictions turned on in Settings.  Be sure to turn it off.
    You are confusing an itunes store account with an icloud account.  You two can continue using the same ID for itunes (thus sharing purchased music, apps, etc.), but you really should have separate accounts (different IDs) for icloud, since an account is intended for one user to keep his/her devices in sync.
    To create a new icloud account, go to
    http://www.apple.com/icloud/setup/
    Then go to Settings>icloud and scroll to the bottom of the screen and tap Delete Account.  (have restrictions turned off)  That will disconnect the device from the account but will not delete data in icloud or other devices.  Then sign in using the new ID.

  • Windows 2008 : How to Restrict Users to Copy file from Shared Folder

    Hello All,
    I need to Restrict Users to Copy file from Shared Folder. Please let me know is there any method to achieve this requirement.

    If user have Read permission, they can copy it. So actually you cannot restrict user from copy your files if they could read/edit.
    Some programs could help restrict users from edit/modify/copy the content of their files such as Office files, PDF files etc as Oscar said above.
    TechNet Subscriber Support in forum |If you have any feedback on our support, please contact [email protected]

  • I need to restrict users to submit data from Smart view or Excel Addin.

    Hi All,
    I need to restrict users to submit data from Smart view or Excel Addin.
    I cant provision them as read access because I want them to write from the Hyperion Planning Web Form.
    Any help on the same will be highily appriciated.

    John,
    Thanks for the reply . if i dont give them essbase write role user cant submit data through smartview or Excel addin. at the same users want to see adhoc reports making connection in smartview through planning, then users can send data.
    1. I want users to restrict export dataform to smartview, if they can export dataform to smartview it automatically makes connection using planning and users can pretty much change data.
    2. is there any way to restrict users making connection through planning in smartview.
    3. when users make smartview connection through essbase, the secuirty works fine and they cant change the data.
    Please let me know if you any solution ....
    advance thanks,
    NM

  • HT4314 I have loaded the game Boggle onto an ipad and if I want to play it info from EA prevents me from doing so?

    I have loaded the game Boggle onto an ipad and if I want to play it info from EA prevents me from doing so?

    Yes, if you have an appleTV it would be easier.   WIthout airplay, you can use APP called BEAMER, beam any video file to your AppleTV hooked to you TV set.
    It would stream more smoothly if you put each video file as you go onto the Mac from the HD, and erase after youre done watching same.
    http://beamer-app.com

  • I use to administrate my DSL modem via an ip-address. When I enter it into FF8 I am asked where to save the file. Why and how can I prevent FF8 from doing that?

    I use to administrate my DSL modem via an ip-address. When I enter it into FF8 I am asked where to save the file. Why and how can I prevent FF8 from doing that?
    And now anytime I am entering an ip-address I am asked if I want to download the file.

    It happens when the modem server doesn't send the file as text/html, but with another MIME type.<br />
    I tried the index.html addition in case the server might send that file as text/html.<br />
    If your DSL modem has a support website then you can try to ask there for advice about how to configure the modem server.

  • I am trying to install a new theme but FF is preventing me from doing so even when I click 'Allow'

    I am trying to install a new theme but FF is preventing me from doing so even when I click 'Allow'. Might someone help?
    Thank you,
    Leeflea

    Do you mean this?
    *Firefox/Tools > Options > Advanced > General : Accessibility : [ ] "Warn me when web sites try to redirect or reload the page"
    The setting in "Tools > Options > Advanced > General" is meant as an accessibility feature, as you can see by the label of that section, so that people with disabilities or people who use screen readers do not get confused and is not meant as a safety protection to stop redirecting.
    See also:
    *https://support.mozilla.org/kb/settings-network-updates-and-encryption#w_general-tab
    *http://kb.mozillazine.org/accessibility.blockautorefresh
    *http://kb.mozillazine.org/Accessibility_features_of_Firefox

  • I'm having a problem with logging into a FileVault-protected user account after restoring from Time Machine backup.

    Hi all,
    My computer had been running really slowly for a while, so I decided to erase the whole hard drive and reinstall the operating system, and then I was going to restore the files I cared about from Time Machine. The main account, which had all my documents and photos, was FileVault-protected. The last thing I did before erasing the hard drive was to run one last Time Machine backup. As far as I remember, I always ran Time Machine backups with the FileVaulted user logged in.
    I don't remember whether I was using FileVault 1 or 2. I had been using FileVault 1, but I installed Lion as soon as it came out and I thought I had migrated to FileVault 2 at that point.
    Once I erased the hard drive and reinstalled the operating system, I browsed the Time Machine disk and, within the Users folder, there was no folder for the main user account. When I tried to reinstall everything by restoring from Time Machine backup, I'd get the option for all the user accounts, but when I tried to log in with the main one I'd get the dreaded "You are unable to log in to the FileVault user account "User" at this time. Log in failed because an error occurred." Finally, when attempting to restore from the Time Machine backup again, I noticed something strange: After the computer got to about 10% done restoring, it declared itself completed successfully and rebooted.
    I've tried a number of tips that came up from questions about similar issues on the Apple support forum, but had no luck. Is there any way to get these files back? Did they ever even get backed up?
    Thanks.

    Hroodbwai wrote:
    I can't find it! not sure what's going on but the only folder shown is the " Shared" folder.
    Did you have only the one user account? If there were others, they should also be in the "Users" folder. You probably won't have access to the files inside them, but they should be there.
    From what can make out, it looks like it's not backed up any of the files for the filevault account. Can't see user folder when looking through previous backups in Time Machine galaxy view.
    Are you doing that from a Finder window set to your internal HD, or your computer name? It should look something like this (with the Finder in List view):
    |
    |
    I'd been logging out and backing up manually on a regular basis.
    Scheduled backups should run normally; but they won't back up the File Vault sparse bundle, nor will any run manually.
    The only time it's backed-up is when you actually log out.
    You should have seen this window on logout:
    |
    |
    followed by this one:
    |
    |
    If you didn't see the second one, or cancelled it, the account wasn't backed-up.

  • Two user accounts after Migration from old Mac

    Yesterday I bought a new iMac with OSX Lion. I used the Setup assistant to move my data from my old iMac (Leopard) using Firewire target disk mode.
    When that was finished, I was suprised not to see any of my old stuff on my new Mac, so I started copying some stuff manually. It was only later that my penny dropped (Lion noobie here) and I realised I now have two user accounts: my new "Lion" account, and another one which - tada - does contain all my old stuff. Both appear to be admin accounts.
    Since I already manually copied all the stuff I wanted to keep to my new account, can I safely delete the old account? How do I do this, and what happens with the old stuff? I read something about the home folder of the deleted user being moved somewhere. Where would that be?
    Thanks!

    It is easy to delete an account but you wisely used the word "safely".  When I migrated to Lion I did an "in place" upgrade and no new adminstrative accounts were created.   Lion will create a guest acount but that can be easily disabled in the Users and Groups preference pane.  Did you do an in place or a clean install of Lion?  
    First, before you delete anything be absolutely sure that the account you want to keep has everything you need.  I suggest you work with it a least a week before making that judgement.  There is no hurry if you have the space to keep two accounts.  I have a spare adminstrative account just in case I need it for troubleshooting.  Be sure you backed up your boot drive with a versioned (like Time Machine) and a cloned backup to an external drive.  
    Go to System Preferences and choose the Users and Groups preference pane.  There you will find your accounts and their designations (i.e. adminstrator, guest, standard).   If you are completely satisfied that the admin account you backed up is all you need then you can click on the lock at the bottom left of that pane, enter your adminstrative password, choose the account you want to delete and click the minus button.  Once you have done this, it is gone.  All of the settings and data you had will be gone unless they were duplicated in another account.  Your applications should remain.  
    That said, there is nothing wrong with having two adminstrator accounts.  Some very security minded people suggest that you should not operate from your admin account because it allows access to deep levels in your computer.  
    Jay

  • File associations are lost when user account is migrated from one domain to another domain (SID changes)

    Hello,
    Currently we are in the middle of a migration project. We are migrating users from child domains to the root domain of one organization.
    The user accounts are migrated with powershell using Move-ADObject cmdlet. This works as expected. The SIDHistory attribute is updated correctly.
    Recently we received complaints from some *migrated* users - they lost their default/custom file associations. This happens only on Windows 8/Windows 8.1.
    What happens:
    the user is migrated and logs on
    her profile loads and everything's preserved (as expected)
    the user clicks on a .jpeg file (previously associated with program XYZ)
    OS asks the user to choose a program to open the file with
    the user chooses a default program XYZ and the file opens
    when the user clicks on a .jpeg file again - OS asks to choose a program again
    i.e. the settings are not preserved.
    Our investigation shows that it is connected with the UserChoice registry key and the HASH value under HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.SomeExt
    According to this blog 
    the HASH is calculated based on user's SID. But after the migration the user has new SID and the HASH becomes invalid and we hit this:
    "However In Win 8, the registry changes are verified by a hash (unique per user and app)  that detects tampering by apps. In the absence of a valid hash, we ignore the default in the registry."
    Currently deleting the UserChoice key for all associations solves the problem. But the user has to make all her customizations again which is undesirable.
    Is there any supported way to fix this? Why the OS doesn't update the HASH after the first logon when the SID has changed as it updates the SID for the ProfileList key? 
    This could become big issue in large migrations.

    Hello Petar K. Georgiev,
    Please check the following article to change the registry key to change back to the default file type associations.
    http://www.sevenforums.com/tutorials/19449-default-file-type-associations-restore.html
    Please note: Since the website is not hosted by Microsoft, the link may change without notice. Microsoft does not guarantee the accuracy of this information.
    Best regards,
    Fangzhou CHEN
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • User accounts have disappeared from the Sys prefs and log-in screen!

    When upgrading to 10.4 from 10.3, I used Carbon Copy Cloner to create a bootable copy of my hard disk to an external (La Cie) drive. After performing an erase and install, the Migration Assistant would not recognize the installation on the external drive. After numerous attempts, I finally re-entered all my settings and transferred most of my files by hand into the new OS. Everything seemed to be fine until I attempted to update the user settings on one of the standard accounts. When I went to the Limitations window for this account in System Preferences the computer froze completely, necessitating a forced shutdown. When I rebooted, the account I was modifying had disappeared from the log-in screen. When I attempted to restore it in Sys Prefs, the Accounts window was blank, and clicking on the resulting items in a Spotlight search gets a preferences error message. I repaired the disk and the permissions with Disk Utility to no avail, and DiskWarrior says the directory is too damaged to rebuild. I re-installed Tiger using archive and install, also with no success. I can log in as Root and access all data, including all user accounts, but still no user accounts in the log-in window or sys prepfs. Does anyone have any thoughts on this before I (aauuugghhh) erase and install again? Any idea why the Migration Asst. can't see the clone? Did I move something into the new OS I shouldn't have?
      Mac OS X (10.4.3)   700mHz G4 iMac (Flat panel)

    When upgrading to 10.4 from 10.3, I used Carbon Copy Cloner to create a bootable copy of my hard disk to an external (La Cie) drive.
    Did you boot into the clone to ensure that it was working just like the original? If so, can you still do that? If so, I'd boot into the clone, use Disk Utility to erase and reformat the internal HD. Then, clone the clone to the original and install Tiger on top of it using the upgrade earlier version option. Then, you won't have to change or migrate anything. IMHO, it's the best way to do it.

  • Multiple User Accounts and Migrating from a hard drive from  MacBook

    After spilling a drink on my old MacBook, which was running a current version of Snow Leopard, I had to pull out my hard drive and migrate my settings and all to a new MacBook Pro. When I first started I didn’t use the set up assistant because I didn’t have a fire wire connection and didn’t realize it was still possible with a USB connection. So I set up a new user account and started to copy files. (ie music, pictures, ect) I then realized I had no idea what I was doing and discovered the Migration Assistant. I ran that and it was great. Everything worked. Problem being, it set up a new user account and duplicated everything I had copied. So now I had 60+GB of duplicated files. Is it possible to remove the bad user account and all files copied into that account? Or should I reset to Manufactures setting? Is that possible?

    PNW Sasquatch wrote:
    Is it possible to remove the bad user account and all files copied into that account?
    Hi, and welcome to the forums.
    Sure. Just log on with an account you're going to keep (preferably an Admin account), go to +System Preferences > Accounts+ and select and delete the one in question. You'll get a prompt that allows you to delete the home folder along with it.

  • Corrupted user account - access files from a different user?

    I am writing with a problem that I've had for about a week now, and which I have been working with an Apple tech support person to resolve, but I figured I would give this forum a shot, as well.
    Last Sunday, my Finder suddenly died on me - I think it was the result of a corrupt file. I first noticed it when I would mouse over my desktop and get a perpetual beachball. I couldn't open a Finder window (or use any applications that rely on accessing my files - iPhoto, iTunes, etc.; the only application that seems to work fine is my internet browser), and when I restarted my computer, I got the same issue when it was back on. I called Apple support and have been working with a senior support rep. We did an archive and install, recreating my old user account named exactly as it had been before. Once I was logged back in, though, I again got the beachball on my desktop. The other admin accounts on the computer do not have the Finder beachball problem, so it is linked specifically to my account. Paul (my tech support friend) recommended that I buy an external hard drive, and if we can't figure out a solution short of backing up my files and erasing my hard drive, we'll do that.
    My question is as follows: will I even be able to access the files on my account from another account if the finder in my account isn't working? I really only want to back up my work files, music, and photos. I can get everything else back. There are now two (or maybe three) admin accounts on my computer - can these accounts access each other's files?
    I appreciate any answers to my question (or any advice you might have for how else I could resolve this situation).
    Thanks!
    Message was edited by: EMV123

    Assuming the problem account has short user name "foo", and one of the other working accounts has short user name "bar", try this:
    1) Log out of the foo account.
    1) Log in as bar.
    2) Open Terminal and enter this:
    su foo (press return, enter foo's password when prompted)
    rm ~/Library/Preferences/com.apple.Finder.plist
    exit
    See if foo's Finder works now.

  • On the iMac user account login screen, what does the checkmark mean?

    On my iMac, I have 3 user accounts. Sometimes I have noticed that next to 1 of the 3 account names that I will sometimes see a small white check mark in a red circle. What does this mean?

    I just received the same login for the first time in a while.  I had left my MacBook Pro asleep for several days and then turned it back on and the wakeup/login screen presented a similar red circle with a white check mark inside.  Did you find an answer?  I created a new post today to see if anyone has had anything similar, not sure if it's firevault or not confirming id...

Maybe you are looking for

  • Macbook Pro won't SD card :(

    I have tried absolutely everything! I don't know what happened as this has always worked for me, I am using Sandisk Ultra 32GB Micro SD card with an adapter and the Mac doesn't recognise it anywhere, even Disk Utility. I have tried connecting my came

  • OS X 10.10.2 and Acrobat 9 Pro

    I just updated to 10.10.2 and now my Adobe Acrobat 9 Pro appears to have lost functionality including OCR and link to Mail. Has anyone else experienced similar problems?

  • BEx Reporting Problem - Display not changing to Text

    Hi SDN Friends, I am working on a task of doing the "out of box" business content reporting on CRM activities, account and contact management ( CRM CIC ). But i installed the business content CRM activities reports in BW, extracted activities transac

  • [Help] NSURLConnection and cache in simulator/device

    Hello, First let me say, I'm fairly new to obj-c / iphone dev, so If some of the questions I may post in the forum sound silly, I'm sorry Right now, I was wondering why when I use the NSURLConnection with default protocol caching policy, in the simul

  • Non riesco ad aggiornare il mio IPhone 5 alla versione iOS 7

    NON RIESCO AD AGGIORNARE IL MIO IPHONE ALLA VERSIONE IOS 7