13-Dec-2004I.Enablersh(orrlogin,...)Installrsh-server*.rpmatfirst.1)/etc/xinetd.d/rshserviceshell{socket_type=streamwait=nouser=rootlog_on_success+=USERI" />

亚洲免费在线-亚洲免费在线播放-亚洲免费在线观看-亚洲免费在线观看视频-亚洲免费在线看-亚洲免费在线视频

Enable rsh/rlogin/rexec in Linux

系統(tǒng) 2309 0

HowTo - rsh, rlogin, rexec
-- for Red Hat Linux distributions --

Karel Zak <kzak redhat.com>
13-Dec-2004

I. Enable rsh (or rlogin, ...)
Install rsh-server*.rpm at first.

1) /etc/xinetd.d/rsh

service shell { socket_type = stream wait = no user = root log_on_success += USERID log_on_failure += USERID server = /usr/sbin/in.rshd disable = no } The option " disable " set to "no".

2) Restart your "xinetd" daemon:

service xinetd restart

3) /etc/securetty
Don't forget check if "rsh" (or "rlogin", ...) is there.

4) Check connection from server to client.
All r[sh | login | exec] utils use two connections. One from client to server and second from server to client.

    - check you client side iptables (firewall, NAT, ...)

5) Check if you server is able to convert client IP address to hostname.

    - check DNS or /etc/hosts

6) Check your ~/.rhosts

    - the best file permissions are "-rw-------"
    - the client hostname must be full hostname, an example:
    foo.bar.com zakkr
7) Check your /etc/pam.d/rsh (or rlogin, ...)
    - for example module "pam_nologin.so" can disable login if the file /etc/nologin exists. For more details read /usr/share/doc/pam-0.77/txts/README.pam_nologin
8) Never change /etc/pam.d/rsh to use somethimeg other than:
    auth required pam_rhosts_auth.so The client-server "rsh" protocol is not designed for other authentication than by .rhost files. For example pam_stack.so in section "auth" can corrupt the client/server connection if the "login" program sends password prompt to client. If you need authentication by password use "rlogin" or "ssh".

II. Notes

1) "rsh" with and without <command> are not same commands

    "/usr/bin/rsh <host>" = is same as "rlogin <host>". It means you need to enabled "rlogin" on server!
    "/usr/bin/rsh <host> <command> = this is normal "rsh"

2) In the Red Hat distributions you can found kerberosized versions of "rsh" (or "rlogin", ...).

    "rsh" without exact path can be interpreted as "/usr/kerberos/bin/rsh".
If you don't need the kerberized version it is better to use absolute path to rsh. You will save yourself the kerberos checking and an execution of the original "rsh" if the kerberos auth fails.

III. Limits

1) The number of privileged ports is limited. The rsh (or rlogin, rcp, ...) uses privileged ports 512-1023. If all ports are used there is no space for a new connection. To check your server's ports status do:

netstat -n --inet

2) TCP/IP connections doesn't end instantly but uses the TIME_WAIT state. The timeout of this state is cca 60s. It's possible that all your reserved ports are in TIME_WAIT state if you use connect and disconnect to server very very often.

IV. Troubleshooting

1) Check /var/log/messages. You can found there a lot of interesing information.

2) Your friend is "strace" program.

    a) client: strace -f -o rsh-client.strace /usr/bin/rsh <host> <command> Don't forget to user the "-f: option, it's important.

    b) server:

    - create shell script "/root/rsh-strace.sh"

    #!/bin/bash /usr/bin/strace -f -o /tmp/rsh-server.trace /usr/sbin/in.rshd - change your /etc/xinetd.d/rsh service shell { socket_type = stream wait = no user = root log_on_success += USERID log_on_failure += USERID server = /root/rsh-strace.sh #/usr/sbin/in.rshd disable = no } The " server " option should be the path to the strace script.

    - restart xinetd daemon

3) Reports bugs to http://bugzilla.redhat.com
It is a good idea to append the strace output to your bug report.

Enable rsh/rlogin/rexec in Linux


更多文章、技術(shù)交流、商務(wù)合作、聯(lián)系博主

微信掃碼或搜索:z360901061

微信掃一掃加我為好友

QQ號聯(lián)系: 360901061

您的支持是博主寫作最大的動力,如果您喜歡我的文章,感覺我的文章對您有幫助,請用微信掃描下面二維碼支持博主2元、5元、10元、20元等您想捐的金額吧,狠狠點擊下面給點支持吧,站長非常感激您!手機微信長按不能支付解決辦法:請將微信支付二維碼保存到相冊,切換到微信,然后點擊微信右上角掃一掃功能,選擇支付二維碼完成支付。

【本文對您有幫助就好】

您的支持是博主寫作最大的動力,如果您喜歡我的文章,感覺我的文章對您有幫助,請用微信掃描上面二維碼支持博主2元、5元、10元、自定義金額等您想捐的金額吧,站長會非常 感謝您的哦?。。?/p>

發(fā)表我的評論
最新評論 總共0條評論
主站蜘蛛池模板: 国产精品婷婷久青青原 | 久久国产亚洲高清观看5388 | 6一10周岁毛片在线 717影院理论午夜伦八戒 | 欧美精欧美乱码一二三四区 | 国产成人免费高清在线观看 | 亚洲日本中文 | 久久国产免费观看精品1 | 免费视频亚洲 | 97精品在线播放 | 日本三级日本三级人妇三级四 | 日本一级特黄a大片在线 | 伊人天天操| 精品一区二区三区在线视频 | 欧美日韩中文一区二区三区 | 欧美成人xxxx | 国产视频自拍一区 | 小说区图片区综合久久亚洲 | 欧美极品福利视频在线播放 | 色狠狠色综合久久8狠狠色 色狠狠婷婷97 | 日日碰日日摸日日澡视频播放 | 伊人久久精品一区二区三区 | 视频福利一区 | 在线欧美v日韩v国产精品v | 亚洲精品三区 | 欧美一级人与动毛片免费播放 | www.99爱| 久久香蕉国产线看观看精品蕉 | 80s成年女人毛片免费观看观看 | 国产精品亚洲国产 | 男人av的天堂| 亚洲瑟瑟| 国产小视频在线观看www | 夜色福利久久久久久777777 | 欧美美女被爆操 | 国产精品久久久久孕妇 | 一级毛片视频在线 | 精品国产成人 | 亚洲精品国产字幕久久vr | 国产一级持黄大片99久久 | 国产精品免费视频能看 | 国产中文字幕第一页 |