运行GNU Screen suid root是使多用户模式工作的唯一方法吗?

时间:2012-02-20 18:50:31

标签: gnu-screen multi-user suid

我正在运行Ubuntu 11.10和GNU Screen版本“4.00.03jw4”,我正在尝试使用多用户模式。

以下过程对我有用:

as user "first_user"
> sudo chmod u+s /usr/bin/screen
> sudo chmod 755 /var/run/screen

and only after that can you do
> screen -S session_name
or if you've already created a screen session,
> screen -r session_name

and inside of screen:
>^A:multiuser on
>^A:acladd second_user "#?"

and if you want second_user to only be an observer
>^A:aclchg second_user -w "#?"

now you can, as user "second_user", do
> screen -x first_user/
to connect 

when you're all done, do 
> sudo chmod u-s /usr/bin/screen
> sudo chmod 775 /var/run/screen

because running screen suid root is a security risk

这令人沮丧。我一直在努力寻找,但我找不到更好的方法。有吗?

1 个答案:

答案 0 :(得分:2)

你是对的。这是实现多用户屏幕运行的唯一方法。

然而,除非您的盒子暴露在外,否则我认为不会留下太大的安全风险。

-Ben