You are not logged in.

#1 2007-01-31 23:51:56

mladen
Member
From: Home
Registered: 2004-03-03
Posts: 46

Deleted 'nobody' - turned out to be very bad idea...

Gals, guys... cool

Few days ago I rounded up a small project:
- Installed and configured Arch on Toshiba Portege 3110ct (no floppy, no CD drive - just connection hub, PXE misbehaved, so ripped the HD to another machine tongue)
- Installed and configured lighttpd (beautifull little http server - configured at no time!)
- Installed and configured Arno firewall
- Installed and configured RootKit Hunter and chkrootkit
- finally, made and moved my web pages to the 'server'.

And this was all fine for few days... until I wanted to help out RKHunter in it's system analysis...
Amongst all other thngs, RKHunter checks and gives info on crontab run for user Nobody. And makes it OK, since no rootkit was found (I hope because there's none wink).
But, to avoid this effort ofr it, *late* last night, I userdel -r nobody.   roll ...Mistake. Now I don't have /bin/bash for any of accouts, root inclusive.

Symptoms are, even while still in current KDE session (opened while I was monkeying around), if I want to open a konsole, it can't keep on the screen. Shows up on the screen and quickly disappears. So, I restarted X, tried another session, but it doesn't even begin - an X window shows up and says something like "... no file /bin/bash" and returns back to Arch login splash.

I didn't power the system down, and checked the web pages serving today from my job and its OK.

Now, question you probably guessed is coming: how to make things back to normal?
Please bear in mind that I don't have CD/DVD access on this machine... Otherwise it would be relatively easy (though I haven't had an issue like this ever before).

Thanks and cheers to all,
mladen

p.s. Or,  could this be one of those accidental "security breakthrough's" - system does the job, but no one can log in and do malice, he, he big_smile:D:D ?)


No past, no future. It's all one long, never ending present.

Offline

#2 2007-02-01 01:22:45

hacosta
Member
From: Mexico
Registered: 2006-10-22
Posts: 423

Re: Deleted 'nobody' - turned out to be very bad idea...

try adding init=/bin/bash to your grub entry, then add the user

Offline

#3 2007-02-01 03:03:52

mladen
Member
From: Home
Registered: 2004-03-03
Posts: 46

Re: Deleted 'nobody' - turned out to be very bad idea...

hmm, sounds simple! Will give it a go once at home!

Thanks even it doesn't work out smile

Last edited by mladen (2007-02-01 03:04:22)


No past, no future. It's all one long, never ending present.

Offline

#4 2007-02-01 23:35:45

mladen
Member
From: Home
Registered: 2004-03-03
Posts: 46

Re: Deleted 'nobody' - turned out to be very bad idea...

No, it didn't work out sad
The only response I could get is "File not found..." (or similar) just before kernel decompresses. And it hangs there.
I guess, I've effectively killed bash and nothing would be executed without it.

So, this machine got reinstalled from 0.8 alpha3 and is running again... Few questions do remain but, for another thread.

Anyway, it would be nice to know what actually happened to the system with user nobody deleted. Anyone!?
(meantime I've leartn a lot on user nobody, but couldn't find the sequence of events after it is deleted.)

Cheers,
mladen


No past, no future. It's all one long, never ending present.

Offline

#5 2007-02-02 14:56:14

Leffe
Member
Registered: 2006-05-30
Posts: 47

Re: Deleted 'nobody' - turned out to be very bad idea...

mladen wrote:

Anyway, it would be nice to know what actually happened to the system with user nobody deleted. Anyone!?

userdel -r removes everything in the user's home directory, nobody's home directory is set to /...  Meaning it's (pretty much) the same as doing rm -Rf /.  Not much can be done to recover from that.

Offline

#6 2007-02-03 09:55:52

mladen
Member
From: Home
Registered: 2004-03-03
Posts: 46

Re: Deleted 'nobody' - turned out to be very bad idea...

rm -Rf /

I learnt it out later. But never felt it before - now I know wink!

It was, actually, kind a surprising that my server was still normally(?)  running after that. Another surprise was a thought that this could be a way to secure running processes - BUT one would need the way to recover... an efficient way...

Thanks Leffe and cheers,
mladen


No past, no future. It's all one long, never ending present.

Offline

#7 2008-02-12 18:50:40

vs.taras
Member
Registered: 2008-02-12
Posts: 5

Re: Deleted 'nobody' - turned out to be very bad idea...

A little off-topic, but how were you able to get the harddrive out?  I have the same model, and can't seem to locate it.
I'm SUCH a n00b
It seems I will have to take the whole thing apart.

Last edited by vs.taras (2008-02-12 18:51:38)

Offline

Board footer

Powered by FluxBB