Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 21 Mar 1997 07:13:42 -0600 (CST)
From:      "Paul T. Root" <proot@horton.iaces.com>
To:        durang@u.washington.edu (K. Marsh)
Cc:        questions@freebsd.com
Subject:   Re: chmod, chown, and shutdown.
Message-ID:  <199703211313.HAA16264@horton.iaces.com>
In-Reply-To: <Pine.A32.3.95.970320160858.52298D-100000@goodall.u.washington.edu> from "K. Marsh" at "Mar 20, 97 04:18:17 pm"

next in thread | previous in thread | raw e-mail | index | archive | help
In a previous message, K. Marsh said:
> My roomate uses my computer to check his e-mail and do a little web
> browsing in FreeBSD, as well as to use Word, Excel, and other expensive
> programs in that other operating system.
> 
> How can I give him the ability to issue "shutdown" without giving him root
> privileges?
> 
> I am aware that it may be a security hole, but he's not going to hack my
> system. I just don't want him to able to destroy everything by accident.
> 
> I tried using chmod and chown on the binary, but even when he owns it and
> it's in 777 mode, it doesn't execute.
> 
> I'm using 2.2-RELEASE if it makes any difference.
> 
> Thanks,   Ken Marsh

I create another user that has shutdown halt or reboot as its login shell.
And have its ID as 0. 

In the past, I've also put halt or reboot on port that you can telnet to
(in inetd.conf). Though I wouldn't recommend either for machines that
connect on the internet.

--
"Yeah, I hit her, but I didn't hit her more than the average guy
 beats his wife."

--Ike Turner, explaining his persistent abuse of his former wife,
  singer, Tina Turner, 1985.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?199703211313.HAA16264>