Re: Limiting Shell Access Damage (was Guruness)

2005-10-24 Thread Bob Beck
Everything said to this point is very good... > > A typical attack vector, however, for 1000+ account sites is a > compromised account. You can assume at least 5 per 1000 accounts are > compromised or have easily guessable passwords. Those will not heed your > policy forms whatever you

Re: Limiting Shell Access Damage (was Guruness)

2005-10-24 Thread Hannah Schroeter
Hello! On Thu, Oct 20, 2005 at 11:01:55PM +0200, Jesper Louis Andersen wrote: >[... what looks like good advice ...] >A typical attack vector, however, for 1000+ account sites is a >compromised account. You can assume at least 5 per 1000 accounts are >compromised or have easily guessable passwo

Re: Limiting Shell Access Damage (was Guruness)

2005-10-24 Thread Jesper Louis Andersen
Will H. Backman wrote: Turning this into a learning experience: Does anyone have any hints or advice about hardening OpenBSD for shell accounts. Do people tweak things other than the login.conf settings? I have to deal with student shell accounts where students are learning to program and oft

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Peter Valchev
> > To clarify, if you limit someone's ram use to a certain point, or > > CPU use to a certain point, it will slow down compiling due to > > having less resources :) As I said though - I may be wrong on > > this one. > > Yes, that would be the idea of limiting resources. If I am given the ability

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Wolfpaw - Dale Corse
> Yes, that would be the idea of limiting resources. If I am > given the ability to use 99% of the CPU compiling software, > how is that different than me running a fork bomb and doing the same? In essanse I suppose it isn't - but if your (as in my case) selling shells, compiling is legitimate,

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Spruell, Darren-Perot
From: Wolfpaw - Dale Corse [mailto:[EMAIL PROTECTED] > > On 10/19/05, Wolfpaw - Dale Corse <[EMAIL PROTECTED]> wrote: > > > quickly. I try not to use limits, because it slows > > compiling to crap > > > :( > > > > this makes no sense whatsoever. > > To clarify, if you limit someone's ram use

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Wolfpaw - Dale Corse
> On 10/19/05, Wolfpaw - Dale Corse <[EMAIL PROTECTED]> wrote: > > quickly. I try not to use limits, because it slows > compiling to crap > > :( > > this makes no sense whatsoever. To clarify, if you limit someone's ram use to a certain point, or CPU use to a certain point, it will slow down

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Ted Unangst
On 10/19/05, Wolfpaw - Dale Corse <[EMAIL PROTECTED]> wrote: > quickly. I try not to use limits, because it slows compiling to crap :( this makes no sense whatsoever.

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Graham Toal
> Turning this into a learning experience: Does anyone have any hints or > advice about hardening OpenBSD for shell accounts. Do people tweak > things other than the login.conf settings? I have to deal with student > shell accounts where students are learning to program and often create > proble

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Wolfpaw - Dale Corse
> Turning this into a learning experience: Does anyone have > any hints or advice about hardening OpenBSD for shell > accounts. Do people tweak things other than the login.conf > settings? I have to deal with student shell accounts where > students are learning to program and often create pr

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Wolfpaw - Dale Corse
> If you can port it, you can also use it on your own box, so > where is the problem? No problem there.. Actually looking at the couple of functions I need here to see how difficult to integrate they would be. > login.conf (5) > > > Problem comes into play when a user starts say .. 50 > > Copie

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Tobias Weingartner
On Wednesday, October 19, "Will H. Backman" wrote: > > Turning this into a learning experience: Does anyone have any hints or > advice about hardening OpenBSD for shell accounts. Do people tweak > things other than the login.conf settings? I have to deal with student > shell accounts where stud

Re: Limiting Shell Access Damage (was Guruness)

2005-10-19 Thread Will H. Backman
> -Original Message- > From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of > knitti > Sent: Wednesday, October 19, 2005 5:23 AM > To: Wolfpaw - Dale Corse > Cc: misc@openbsd.org > Subject: Re: Guruness (was the bug report thread) > > On 10/19/05, Wolfpaw - Dale Corse <[EMAIL PRO