Validate user/shell to prevent stuck login
This commit is contained in:
@@ -57,10 +57,27 @@ if [ "${TARGET}" != 'ALL' ]; then
|
|||||||
JAILS=$(jls name | grep -w "${TARGET}")
|
JAILS=$(jls name | grep -w "${TARGET}")
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
validate_user() {
|
||||||
|
if jexec -l ${_jail} id "${USER}" >/dev/null 2>&1; then
|
||||||
|
USER_SHELL="$(jexec -l ${_jail} getent passwd "${USER}" | cut -d: -f7)"
|
||||||
|
if [ -n "${USER_SHELL}" ]; then
|
||||||
|
if jexec -l ${_jail} grep -qwF "${USER_SHELL}" /etc/shells; then
|
||||||
|
jexec -l ${_jail} /usr/bin/login -f "${USER}"
|
||||||
|
else
|
||||||
|
echo "Invalid shell for user ${USER}"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "User ${USER} has no shell"
|
||||||
|
fi
|
||||||
|
else
|
||||||
|
echo "Unknown user ${USER}"
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
for _jail in ${JAILS}; do
|
for _jail in ${JAILS}; do
|
||||||
echo -e "${COLOR_GREEN}[${_jail}]:${COLOR_RESET}"
|
echo -e "${COLOR_GREEN}[${_jail}]:${COLOR_RESET}"
|
||||||
if [ ! -z "${USER}" ]; then
|
if [ ! -z "${USER}" ]; then
|
||||||
jexec -l ${_jail} /usr/bin/login -f "${USER}"
|
validate_user
|
||||||
else
|
else
|
||||||
jexec -l ${_jail} /usr/bin/login -f root
|
jexec -l ${_jail} /usr/bin/login -f root
|
||||||
fi
|
fi
|
||||||
|
|||||||
Reference in New Issue
Block a user