Restrict shell loop
Posted: Sun Mar 20, 2016 5:26 pm
How to restrict shell loop commands by RBAC?
A simplest DoS for example
etc...
"RES_CPU 50 100" was set in "subject /bin/bash", but it not solved this issue.
A simplest DoS for example
- Code: Select all
localhost ~ # while true; do echo 1 > /dev/null ; done &
[9] 3680
localhost ~ # while true; do echo 1 > /dev/null ; done &
[10] 3681
localhost ~ # while true; do echo 1 > /dev/null ; done &
[11] 3682
localhost ~ # while true; do echo 1 > /dev/null ; done &
[12] 3683
etc...
"RES_CPU 50 100" was set in "subject /bin/bash", but it not solved this issue.