Hacker News new | ask | show | jobs
by 0cf8612b2e1e 2 hours ago
I suppose /usr/sbin/nologin is not a thing?

https://www.man7.org/linux/man-pages/man8/nologin.8.html

1 comments

That's a hack. It's a login shell that, once you have already logged in and run the shell, prints a message saying you can't log in or run a shell, and then exits.

It does not stop you from, say, logging in to SSH and then starting a port forward. Or running a command in a way that bypasses the login shell. ssh will always pass it to your login shell but other ways can be vulnerable.

Do you have a script to show us how it works? Here, use mine. There's no password. Only 1 person permitted on your keyboard. If you have two people typing on it at the same time that's cheating.

    sftp ai@nochan.net