preventing .rhost write

2007-12-25 5:13:00

Hi all,

I was wondering if there was a way to prevent users from modifying the
.rhost file.

We have a situation where only some users are permitted to rsh over from
one box to anther. It's controlled by SeOS. In an effort to reduce cost
we are looking for alternatives.

I was thinking we could have the .rhost file owned by root with 444
permissions on the file. This would allow the process to continue
working but would prevent the user from modifying his own file.

Only problem is the user can delete it and recreate it.

Is there a ACL that would prevent that from occurring?

Any other ideas?

Thanks in advance

George Genovezos, CISSP, CIFI
Senior Security Analyst
Sabre Holdings Inc.
Southlake, TX US 76092

Comments

Got something to say?

You must be logged in to post a comment.