[asterisk-users] giving a user asterisk CLI access: how bad could it get

Tzafrir Cohen tzafrir.cohen at xorcom.com
Fri Oct 31 06:28:02 CDT 2008


On Fri, Oct 31, 2008 at 11:11:08AM +0100, fadey wrote:
> Hi, everyone
> 
> I'm investigating if I could give asterisk CLI access to one of our
> clients.
> If I add that user to asterisk group and set his shell
> to /usr/sbin/rasterisk, is there a possibility for a user to brake our
> of asterisk CLI to normal shell?

The shell is something that should be run at login time. Asterisk is not
such a program. It will not be run directly anyway. Set the shell to
either /bin/sh (/bin/bash , /bin/dash , whatever) if you want to allow
that user to login, or to /bin/false if you don't .

-- 
               Tzafrir Cohen
icq#16849755              jabber:tzafrir.cohen at xorcom.com
+972-50-7952406           mailto:tzafrir.cohen at xorcom.com
http://www.xorcom.com  iax:guest at local.xorcom.com/tzafrir



More information about the asterisk-users mailing list